Vision Helpdesk 3.9.10 Stable File Upload

2016.08.23
id HXn (ID) id
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

############################################################## > Exploit Title: Reg user Helpdesk File Upload > Exploit Author: HxN | facebook.com/CowoKerensTeam > Dork : inurl:"Powered by Vision Helpdesk 3.9.10 Stable" > Website : https://www.visionhelpdesk.com/ > Date : 2016/08/23 > Tested on : Ubuntu , Win 8 ############################################################ Edit avatar: 1.Fill all Form 2.Login user 3.Edit Profile 4.Edit Picture & Upload file ############################################################## Upload file shell or Script : shell.php.jpg / script.htm ############################################################### Demo: https://www.resellerbox.com/support/awatar/phpawTo4e http://support.chargerssoccer.com/awatar/php8GyTvU http://support.evermorevitality.com/avatar/phpiYcpp6 http://www.support.evermorejv.com/avatar/phpP2KRdb http://helpdesk.tabscomputer.co.uk/avatar/phpB1DIx7 http://helpdesk.ourinternet.us/avatar/php4UtwyK http://support.hostafirm.com/avatar/phpUHLF5A http://helpdesk.cloud2business.dk/avatar/php0vCvrZ


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top