Jump to content
Nytro

PHP LFI to Arbitrary Code Execution via rfc1867 File Upload Temporary Files

Recommended Posts

PHP LFI to Arbitrary Code Execution via rfc1867 File Upload Temporary Files

by Gynvael Coldwind

18 March 2011

Prologue

This article describes a method of taking advantage of a .php script Local File

Inclusion vulnerability. It does not describe any vulnerability in the PHP engine

itself, nor does it describe any new vulnerability class.

Download:

http://www.exploit-db.com/download_pdf/17010

L-am citit, e scurt dar prezinta o idee interesanta. Vi-l recomand.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...