56 lines
No EOL
2.6 KiB
Text
56 lines
No EOL
2.6 KiB
Text
==========================================================
|
|
Holiday Travel Portal Upload Vulnerability
|
|
==========================================================
|
|
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
|
|
0 _ __ __ __ 1
|
|
1 /' \ __ /'__`\ /\ \__ /'__`\ 0
|
|
0 /\_, \ ___ /\_\/\_\ \ \ ___\ \ ,_\/\ \/\ \ _ ___ 1
|
|
1 \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ 0
|
|
0 \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/ 1
|
|
1 \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ 0
|
|
0 \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ 1
|
|
1 \ \____/ >> Exploit database separated by exploit 0
|
|
0 \/___/ type (local, remote, DoS, etc.) 1
|
|
1 1
|
|
0 [+] Site : Inj3ct0r.com 0
|
|
1 [+] Support e-mail : submit[at]inj3ct0r.com 1
|
|
0 0
|
|
1 ########################################## 1
|
|
0 I'm Sid3^effects member from Inj3ct0r Team 1
|
|
1 ########################################## 0
|
|
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1
|
|
|
|
Name : Holiday Travel Portal Upload Vulnerability
|
|
Date : june, 8 2010
|
|
Vendor url :http://www.tourismscripts.com/scripts/
|
|
Price: 299 Euro
|
|
Author : Sid3^effects aKa HaRi <shell_c99[at]yahoo.com>
|
|
special thanks to : r0073r (inj3ct0r.com),MaYur,LiquidWorm,gunslinger_
|
|
greetz to :All ICW members.
|
|
|
|
###############################################################################################################
|
|
Description:
|
|
|
|
Our comfortable Accommodation Hotel Booking Portal for all kind of accommodation
|
|
hotels, hostels, apartments, guest house, finca, motels .....
|
|
villas, houses, flats, Yachts, Tours, Cities ....
|
|
|
|
###############################################################################################################
|
|
Xploit: Upload Vulnerability
|
|
|
|
STEP 1 : REgister as a user :)
|
|
|
|
STEP 2 : demo url for loggin in
|
|
|
|
DEMO URL : http://server/user/?
|
|
|
|
STEP 3 : Once logged in go to edit profile to upload your evil script with an extension .php.jpg :)
|
|
|
|
STEP 4 : Go to your shell
|
|
|
|
DEMO URL : http://server/user/uploads/small_thumbs/testphpjpeg.php.txt.txt.txt
|
|
|
|
STEP 5 : And there your are :)
|
|
|
|
###############################################################################################################
|
|
#Sid#^effects |