____________________ ___ ___ ________ \_ _____/\_ ___ \ / | \\_____ \ | __)_ / \ \// ~ \/ | \ | \\ \___\ Y / | \ /_______ / \______ /\___|_ /\_______ / \/ \/ \/ \/ .OR.ID ECHO_ADV_56$2006 ------------------------------------------------------------------------------ [ECHO_ADV_56$2006] P-Book <= 1.17 (pb_lang) Remote File Inclusion ------------------------------------------------------------------------------ Author : Ahmad Maulana a.k.a Matdhule Date Found : October, 18th 2006 Location : Indonesia, Jakarta web : http://advisories.echo.or.id/adv/adv56-matdhule-2006.txt Critical Lvl : Highly critical Impact : System access Where : From Remote --------------------------------------------------------------------------- Affected software description: ~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Application : P-Book version : 1.17 URL : http://www.PPoPn.net --------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~~~~~ I found vulnerability script admin.php -----------------------admin.php---------------------- ....