|
---------------------------------------------------------------
____ __________ __ ____ __
/_ | ____ |__\_____ \ _____/ |_ /_ |/ |_
| |/ \ | | _(__ <_/ ___\ __\ ______ | \ __\
| | | \ | |/ \ \___| | /_____/ | || |
|___|___| /\__| /______ /\___ >__| |___||__|
\/\______| \/ \/
---------------------------------------------------------------
Http://www.inj3ct-it.org Staff[at]inj3ct-it[dot]org
Original Here: http://www.inj3ct-it.org/exploit/scribe.txt
---------------------------------------------------------------
Scribe <= 0.2 Remote PHP Code Execution
---------------------------------------------------------------
#By KiNgOfThEwOrLd
---------------------------------------------------------------
PoC:
When we register a news user, scribe make a file called [username].php located in /regged/. The file contains:
Username: [username]
---------------------------------------------------------------
Exploit:
Now, go on:
http://[target]/[scribe_path]/regged/