[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

FORMfields Upload Vulnability

Author
PretoriaN
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15589
Category
web applications
Date add
13-03-2011
Platform
php
# Date: [12.03.2011]
# Author: [PretoriaN]
# Vendor or Software Link: 
# Version: [app version]
# Category:: [Exploit]
# Google dork: [inurl:/forms/FORMfields/]
# Tested on: [PHP]
#Exploit:/examples/allFields/ffce_all_fields.php#upload

Step 1: in Text Field: type any name 
Step 2: Image Verification: Write iamge verification
step 3: in Upload Field chose your index and type Save

And you will se a link where The Index has been Located
# Demo site: [http://www.libyaonline.com/forms/FORMfields/examples/allFields/ffce_all_fields.php#upload]
  Demo 2:    [http://www.corindagolfcourse.com.au/forms/FORMfields/examples/allFields/ffce_all_fields.php#upload}
  
  Uploaded index: http://www.corindagolfcourse.com.au/forms/FORMfields/uploads/hackmaster-upload-1299938246.htm

  Greetz to all Albanian Hackers 

PretoriaN 

Bledi@kosovadc.com



#  0day.today [2024-12-26]  #