Senin, 07 Maret 2011

RuubikCMS < v1.0.3 Shell Upload Vulnerability

Exploit Title : RuubikCMS < v1.0.3  Shell Upload Vulnerability
 
Google Dork : Powered by RuubikCMS
 
Date : 2011-03-06
 
Author : Alexander
 
Software Link : http://www.ruubikcms.com
 
Version : < v1.0.3
 
Test On : Linux/php
 
CVE : Web Applications
 
###########################################################################
 
===[ Exploit ]=== 
 
http://server/[patch] /tiny_mce/plugins/tinybrowser/tinybrowser.php
 
Select the Upload And Then Browse File.gif
 
===[ Upload To ]===
 
http://server/[patch]/useruploads/images/File.gif
 
OR
 
http://server/[patch] /upload/image/File.gif
 
===[ Demo ]===
 
http://server/ruubikcms/tiny_mce/plugins/tinybrowser/tinybrowser.php
 
 
http://www.1337day.com

 
blogger templates