[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Availscript Classmate Script Remote File Upload Vulnerability

Author
S.W.A.T.
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4448
Category
web applications
Date add
14-12-2008
Platform
unsorted
=============================================================
Availscript Classmate Script Remote File Upload Vulnerability
=============================================================


[~] Availscript Classmate Script Remote File Upload Vulnerability
[~]
[~] ----------------------------------------------------------
[~] Discovered By: S.W.A.T.  
[~]
[~] Home: www.batlagh.com
[~]
[~] Script Page: http://www.availscript.com/classmate_script.php
[~] -----------------------------------------------------------

Xpl:

1.First Register Into The Site ( link: www.site.com/[path]/register.php )

2.In Register Section Select Your phpshell like: c99.php

3.In "Latest Members" Section Right Click On Blank Line & Then Choose Properties

4.Copy The Link Of Your Shell Like: http://www.availscript.com/classmate/memberspics/saeid-61609-c99.php

5.Your Shell Will Be Renamed With Your Name & Random ID like: saeid-61609-c99.php

6.Hack The Site ;)


Demo:

http://www.availscript.com/classmate/



#  0day.today [2024-11-15]  #