[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Dotclear 2.4.2 Arbitrary File Upload Vulnerability

Author
T0x!c
Risk
[
Security Risk Medium
]
0day-ID
0day-ID-17586
Category
web applications
Date add
27-02-2012
Platform
php
#### # Exploit Title: dotclear-2.4.2 (Swf) File Upload Vulnerability
# Author: T0x!c
# Date: 2012/02/24
# Facebook Page: www.facebook.com/DzTem
# E-mail: Malik_99@hotmail.fr
# Category:: webapps
# Google Dork: "powered by dotclear"
# Vendor: http://fr.dotclear.org/download
# Version: 2.4.2
# Tested on: [Windows Xp]
####
# Exploit :
http://www.example.com/path/inc/swf/swfupload.swf
you can upload files with php extension.
Example: c99.php, shell.gif.php, etc...
=================================**AlgeriansHackers**==================================
# Greets To : KedAns-Dz * Caddy-Dz * Kha&miX * Jago-dz * Nassim24Missil * Kalashinkov *
(exploit-id.com) , (1337day.com) , (dis9.com.com) ,  (Dz-Team.biz)
=======================================================================================



#  0day.today [2024-11-15]  #