____________________ ___ ___ ________ \_ _____/\_ ___ \ / | \\_____ \ | __)_ / \ \// ~ \/ | \ | \\ \___\ Y / | \ /_______ / \______ /\___|_ /\_______ / \/ \/ \/ \/ .OR.ID ECHO_ADV_33$2006 --------------------------------------------------------------------------- [ECHO_ADV_33$2006] CMS Faethon 1.3.2 mainpath Remote File Inclusion --------------------------------------------------------------------------- Author : M.Hasran Addahroni a.k.a K-159 Date : June, 16th 2006 Location : Indonesia, Bali Web : http://advisories.echo.or.id/adv/adv33-K-159-2006.txt Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ CMS Faethon Application : CMS Faethon version : 1.3.2 URL : http://cmsfaethon.com/ Description : CMS Faethon is content management system for different web pages. --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~~~ in folder data we found vulnerability script header.php. -----------------------header.php---------------------- ....