exploit-db-mirror/exploits/php/webapps/13892.txt
Offensive Security d304cc3d3e DB: 2017-11-24
116602 new exploits

Too many to list!
2017-11-24 20:56:23 +00:00

33 lines
No EOL
1.1 KiB
Text
Raw Blame History

This file contains invisible Unicode characters

This file contains invisible Unicode characters that are indistinguishable to humans but may be processed differently by a computer. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.

Name : PHPAuctionSystem Upload Vulnerability
Date : june, 16 2010
Vendor url :http://www.phpauctions.info/
Critical Level     : HIGH
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,gunslinger_
greetz to :All ICW members and my friends :) luv y0 guyz
#######################################################################################################
 
PHPAuctionSystem had various vulnerablities which was found
#######################################################################################################
Xploit:Upload Vulnerability
 Step 1: register as a user :)
 
 Step 2: goto "sell an item" option
 DEMO URL :http://[site]/select_category.php?
 Step 3: post ur evil-code in the item description
 Step 4:check your item and ur evil script is executed and upload your shell and enjoy :P
 demo url :http://[site]/sell.php :)
###############################################################################################################
# 0day no more
# Sid3^effects