Back to list
Lazarus Guestbook (admin.php)Remote File Include Expliot
Mar 07 2007 11:23PM
c_r_ck hotmail com
Re: [Bogus] Lazarus Guestbook (admin.php)Remote File Include Expliot -
Mar 08 2007 01:23AM
Mailinglists Address (mailinglist expresshosting net)
c_r_ck (at) hotmail (dot) com [email concealed] wrote:
> # Lazarus Guestbook (admin.php)Remote File Include Expliot
> # D.Script: http://www.carbonize.co.uk
> # Dork: "Powered by Lazarus Guestbook from carbonize.co.uk"
> # Discovered by Crack_man
> # Homepage: http://www.b0rizq.biz
> # Greetz To :B0rizq & red_casper & Draknaz kaiba & broken_proxy and all freind
> # Exploit:
> # [VicTim]/[path]/admin.php?include_path=shell.txt?cmd
With the lack of version information in this report it is hard for me to
say if the version I downloaded was already a patched version, or if
(based on previous history of these types of posts) this is just another
bogus report where the reviewer didn't actually look at the code, and
just posted based on the fact that there was a variable used in an
include (require, include_once, require_once, fopen, etc...) call.
Looking at line 36 of the admin.php script you can see the following:
$include_path = dirname(__FILE__);
So... either it is patched in the version I am looking at (unlikely) or
this is a bogus report (like god knows how many others).
Express Web Systems, Inc.
[ reply ]
Copyright 2010, SecurityFocus