Realist

Wednesday 4 October 2017, 23:46  #1
Realist P0wn3d
frankgrimes
  • 11 posts

I have downloaded and reviewed the source code of CMSimple. I have determined that the white screen of death that appears when leveraging lfi on files is due to double including things. This causes things to be re-declared blowing up the app. Through experimentation I have determined that using the LFI to include a particular file, if the code within the app to include that file is removed from the program, would make it possible to render without errors and get the flag. Unfortunately, this include directive does exist and causes a php error. Does this somehow need to be bypassed to get the flag? Am I on the right track here?

Wednesday 17 January 2018, 20:26  #2
Realist P0wn3d
caseyvsilver
  • 4 posts

their is a known exploit for cmsimple version 3.0 that is an LFI, that is majority of the answer

Tuesday 20 February 2018, 21:29  #3
Realist - P0wn3d
har0crat3s
  • 1 posts

I have no idea what should I do now, I used a https://www.exploit-db.com/exploits... to upload some file to server, but I can’ find it in /downloads/ (404)
What I am doing wrong?
help please.
PS: I attach the file with the exploit


hack-4.zip (Zip, 523 bytes)
Tuesday 20 March 2018, 16:30  #4
Realist P0wn3d
grzybek
  • 2 posts

Why I can’t verify the solution ?

Still have:
Unable to take account of your message. Thank you to resubmit!

Not only in this challange :(

Regards,
grzybek

Tuesday 27 March 2018, 14:54  #5
Realist P0wn3d
silent-control
  • 3 posts

I need help !
i have found the vulnerability but somehow i cannot find the file i uploaded(not sure if it got uploaded correctly) i used the exploit-db exploit.
Can someone PM and till me what i am doing wrong?

Sunday 22 April 2018, 03:15  #6
Realist P0wn3d
backgr0und
  • 1 posts

I am also having the same issue!

If anyone has any clues for me, let me know...