Vulnerability Information:
Affected program: PHP168 all versions with template editing
Author: esnra
Released on:Http://www.3hack.com
Condition of exploits: You have the permission to enter the background.
Usage:
Go to the function center, find style/template settings, and select style management.
From: http://3hack.com/thread-13128-1-1.html Author: esnra 
Right-click the icon:
 
Select
Copy link address (in Firefox)
Obtain the address, for example:Copy content to clipboardCode:Http://www.3hack.com/ /index.php? Lfj=style&job;editcode&keywords=defa&&filename=head.htmUnable to copy in IE. The property displays the connection address of the image.
Later, replace head.htm with.../../php168/mysql_config.php (likewise, you can replace it with another file path)
Access (Note: it is best to use Firefox to access, YES! U can be accessed using IE, but cannot be accessed. It will be stuck in the background)
The contents of mysql_config.php are displayed!
Applicable Conditions:
No modification permission. The website File Permission is 0755 (running)
No matter how you pass the shell, you do not have the operation permission.
At this time, if you check the MYSQL information, there may be a root waiting for you.