Mostrando postagens com marcador upload. Mostrar todas as postagens
Mostrando postagens com marcador upload. Mostrar todas as postagens
terça-feira, 26 de novembro de 2013
Wordpress Themes Pinboard Arbitrary File Upload Vulnerability
EXPLOIT WP ~~~
#Author : ReC0ded
#Vendor : http://themify.me/
#Download : http://themify.me/themes/Pinboard
#Date : 22, November 2013.
#Type : php, html, htm, asp, etc.
#Category : Web Applications
#Vulnerability : File Upload
#Dork[1] : inurl:/wp-content/themes/pinboard/
#Dork[2] : inurl:site:br /themes/pinboard/
#Dork[3] : inurl:/themes/pinboard/ ext:php
Falha:
#Exploit : http://SITEWPVULL.COM.BR/{PASTA}/wp-content/themes/pinboard/themify/themify-ajax.php
ARQUIVO UPADO:
http://SITEWPVULL.COM.BR/{PASTA}/wp-content/themes/pinboard/uploads/{ARQUIVO}.php
EXPLOIT UPLOAD:http://pastebin.com/FwSP3bQT
segunda-feira, 14 de outubro de 2013
Exploit: FlashChat File Upload.
Exploitando FlashChat
Software Link0x3A3A3A3A http://www.tufat.com/script2.htm
Vs0x3A3A3A3A v6.0.8, v6.0.2, v6.0.4, v6.0.5, v6.0.6, v6.0.7
Modo de uso0x3A3A3A3A
Defina url alvo http://alvo//pasta/chat/ ou http://alvo/chat/
Usando:
http://localhost/exploit.php?url=http://www.thenorfolkbroads.org/forum/chat/
REF:http://www.exploit-db.com/exploits/28709/
Exploit
DORK[0]0x3A3A3A3A intitle:"FlashChat v6.0.8" ext:php
By0x3A3A3A3A GoogleINURL
Scirpt: http://pastebin.com/GgF9Sr8L
Assinar:
Postagens (Atom)