手机
当前位置:查字典教程网 >网络安全 >Exploit >PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability
PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability
摘要:vBulletinPhotoPostvBGalleryv2.xRemoteFileUploadFoundby:Coldz3roe-mail:...

vBulletin PhotoPost vBGallery v2.x Remote File Upload

Found by : Cold z3ro

e-mail : exploiter@hackteach.org

Home page : www.Hack.ps

==============================

exploit usage :

http://localhost/Forum/$gallery_path/upload.php

here the exploiter can upload php shell via this script

by renamed it's name to $name.php.wmv

but first he should be a user in the forum

thats so important to him cus the uploaded file will be

in his account nomber folder .

example :

user : Cold z3ro

http://www.hackteach.org/cc/member.php?u=4

his account nomber is 4 as shown in link ,

the uploaded file ( shell ) will be in

http://localhost/Forum/$gallery_path/files/4/$name.php.wmv

id the user Cold z3ro have acconut nomber as example ( 12345 )

the file path is

http://localhost/Forum/$gallery_path/files/1/2/3/4/5/$name.php.wmv

===================

i want tho thank all members in www.hackteach.org forums , best work u are done.

thank u .

# hackteach.org

【PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability】相关文章:

Easy Photo Gallery 2.1 XSS/FD/Bypass/SQL Injection Exploit

Maian Uploader

Maian Music 1.0 Insecure Cookie Handling Vulnerability

ESET Smart Security 3.0.667.0 Privilege Escalation PoC

WebCMS Portal Edition (id) Remote SQL Injection Vulnerability

MFORUM 0.1a Arbitrary Add-Admin Vulnerability

BrewBlogger 2.1.0.1 Arbitrary Add Admin Exploit

Maian Cart 1.1 Insecure Cookie Handling Vulnerability

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

Maian Greetings 2.1 Insecure Cookie Handling Vulnerability

精品推荐
分类导航