ZonGG Remote Shell Upload Vulnerability

2013.08.07
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

|*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*| |-------------------------------------------------------------------------| | [+] Exploit Title:ZonGG Remote Shell Upload Vulnerability | | [+] Google Dork:site:.gov.cn inurl:"/zongg/" | | [+] Exploit Author: Ashiyane Digital Security Team | | [+] Tested on: Windows,Linux | |-------------------------------------------------------------------------| |-------------------------------------------------------------------------| | [+]Vendor Home :http://zon.cn/down | |-------------------------------------------------------------------------| | [+] Exploit: | | [+] http://localhost/[path]/zongg/upload.asp | |-------------------------------------------------------------------------| | [+] Demo site: | [+] http://www.sXz.gov.cn/zongg/upload.asp | [+] http://www.juX.gov.cn/Zongg/upload.asp | [+] http://www.sqXz.gov.cn/zongg/upload.asp | [+] http://www.hXianedu.gov.cn/zongg/upload.asp | [+] http://www.sqXz.gov.cn/zongg/upload.asp |-------------------------------------------------------------------------| | [+] Uploaded Files: | | [+] http://localhost/upimg/filename | |-------------------------------------------------------------------------| | [+] Discovered By :hossein19123 & Ba3bak | | [+]Greetz to: My Lord Allah | [+]Sp Tnx To:PrinceofHacking , C4T , V1R4N64R , MR.SAMAN, Tr0janman | [+]Ashiyane Security [ Researcher Team AND Deface Team ] |-------------------------------------------------------------------------| | [+]Home:Ashiyane.Org | |-------------------------------------------------------------------------| |*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*||*|

References:

http://zon.cn/down


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top