######################################################## # # Exploit Title : Php Enter Php Code Injection # # Author : IrIsT.Ir & Sec4Ever.com # # Discovered By : L3b-r1'z # # Home : http://IrIsT.Ir & http://Sec4Ever.com # # P Blob : http://L3b-r1z.com/ # # Software Link : http://www.phpenter.net/ # # Security Risk : High # # Version : beta # # Tested on : win\XP # # Dork : allintext: "Powered by phpEnter.net" # # 1) Info Script # 2) Info Vulnerability # 3) P0c # ######################################################## # # 1) Info Script: # # PHP Enter is a free and Open Source PHP News Publishing script. # It is an online news publishing system that features easy installation, user submission. # and an admin panel for adding, editing and removing categories and news. ######################################################## # # 2) Info Vulnerability : # # This exploit allow attacker to inject php code execution like system($_GET['cmd']); # In file named banners in admin folder : # # 1.