手机
当前位置:查字典教程网 >网络安全 >Exploit >PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability
PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability
摘要:vBulletinPhotoPostvBGalleryv2.xRemoteFileUploadFoundby:Coldz3roe-mail:...

vBulletin PhotoPost vBGallery v2.x Remote File Upload

Found by : Cold z3ro

e-mail : exploiter@hackteach.org

Home page : www.Hack.ps

==============================

exploit usage :

http://localhost/Forum/$gallery_path/upload.php

here the exploiter can upload php shell via this script

by renamed it's name to $name.php.wmv

but first he should be a user in the forum

thats so important to him cus the uploaded file will be

in his account nomber folder .

example :

user : Cold z3ro

http://www.hackteach.org/cc/member.php?u=4

his account nomber is 4 as shown in link ,

the uploaded file ( shell ) will be in

http://localhost/Forum/$gallery_path/files/4/$name.php.wmv

id the user Cold z3ro have acconut nomber as example ( 12345 )

the file path is

http://localhost/Forum/$gallery_path/files/1/2/3/4/5/$name.php.wmv

===================

i want tho thank all members in www.hackteach.org forums , best work u are done.

thank u .

# hackteach.org

【PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability】相关文章:

Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit

moziloCMS 1.10.1 (download.php) Arbitrary Download File Exploit

Scripteen Free Image Hosting Script 1.2 (cookie) Pass Grabber Exploit

pSys 0.7.0 Alpha Multiple Remote File Inclusion Vulnerability

Maian Cart 1.1 Insecure Cookie Handling Vulnerability

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

ITechBids 7.0 Gold (XSS/SQL) Multiple Remote Vulnerabilities

Ultra Office ActiveX Control Remote Arbitrary File Corruption Exploit

ESET Smart Security 3.0.667.0 Privilege Escalation PoC

Dreampics Builder (page) Remote SQL Injection Vulnerability

精品推荐
分类导航