| # Title : Subdreamer CMS-v3.7.1 Mullti Vulnerability
| # Author : indoushka
| # email : indoushka4ever@gmail.com
| # Dork : Website powered by Subdreamer CMS & Sequel Theme Designed by indiqo.media
| # Tested on: win8.1 Fr V.(Pro) 23:09 * 22/05/2015
| # Download : http://www.20script.ir
=======================================
Directory listing :
http://127.0.0.1/Subdreamer/admin/tiny_mce/
http://127.0.0.1/Subdreamer/admin/login/
Remote/Local File Inclusion :
C:\web\www\Subdreamer\index.php
Line :1097
Function :include
Variables :$headerfile
Php Code Execution :
C:\web\www\Subdreamer\index.php
Line : 1616
Function : eval
Variables : $layout_arr,$layout_index
LFI :
http://127.0.0.1/Subdreamer/admin/tiny_mce/plugins/imagemanager/imagemanager.php?folderpath=****
Upload File :
C:\web\www\Subdreamer\admin\tiny_mce\plugins\imagemanager\imagemanager.php
Line : 262
Function : move_uploaded_file
Variables : $image['tmp_name'],$imagesdir,$imagesdir
Subdreamer CMS - Admin Panel
Greetz :
jericho http://attrition.org & http://www.osvdb.org/ * packetstormsecurity.com * http://is-sec.org/cc/
Hussin-X * Stake (www.v4-team.com) * D4NB4R * ViRuS_Ra3cH * yasMouh * https://www.corelan.be * exploit4arab.net
---------------------------------------------------------------------------------------------------------------