Parceiro: Camisetas Hacker

Camisetas para Nerds & Hackers

Mostrando postagens com marcador upload. Mostrar todas as postagens
Mostrando postagens com marcador upload. Mostrar todas as postagens

terça-feira, 26 de novembro de 2013

Wordpress Themes Pinboard Arbitrary File Upload Vulnerability

BUG WP THEMES PINBOARD


EXPLOIT WP ~~~
#Author : ReC0ded
#Vendor : http://themify.me/
#Download : http://themify.me/themes/Pinboard
#Date : 22, November 2013.
#Type : php, html, htm, asp, etc.
#Category : Web Applications
#Vulnerability : File Upload


#Dork[1] : inurl:/wp-content/themes/pinboard/
#Dork[2] : inurl:site:br /themes/pinboard/
 #Dork[3] : inurl:/themes/pinboard/ ext:php

Falha:
#Exploit : http://SITEWPVULL.COM.BR/{PASTA}/wp-content/themes/pinboard/themify/themify-ajax.php

ARQUIVO UPADO:

http://SITEWPVULL.COM.BR/{PASTA}/wp-content/themes/pinboard/uploads/{ARQUIVO}.php


EXPLOIT UPLOAD:http://pastebin.com/FwSP3bQT

segunda-feira, 14 de outubro de 2013

Exploit: FlashChat File Upload.

Exploitando FlashChat 

Exploit: FlashChat File Upload.
Software Link0x3A3A3A3A http://www.tufat.com/script2.htm
Vs0x3A3A3A3A v6.0.8, v6.0.2, v6.0.4, v6.0.5, v6.0.6, v6.0.7

Modo de uso0x3A3A3A3A
Defina url alvo http://alvo//pasta/chat/ ou http://alvo/chat/
Usando:  
http://localhost/exploit.php?url=http://www.thenorfolkbroads.org/forum/chat/ 

REF:http://www.exploit-db.com/exploits/28709/

Exploitando FlashChat

Exploit
Exploit

DORK[0]0x3A3A3A3A intitle:"FlashChat v6.0.8" ext:php

By0x3A3A3A3A GoogleINURL

Scirpt: http://pastebin.com/GgF9Sr8L