header-logo
Suggest Exploit
vendor:
Rapidshare
by:
Hussin X
7.5
CVSS
HIGH
Remote Shell Upload Vulnerability
434
CWE
Product Name: Rapidshare
Affected Version From: 1.0.0
Affected Version To: 1.0.0
Patch Exists: No
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2009

AJA Modules Rapidshare 1.0.0 Remote Shell Upload Vulnerability

A vulnerability exists in AJA Modules Rapidshare 1.0.0 which allows an attacker to upload a malicious shell to the server. The attacker can change the type of shell from c99.Php to c99.php.rar and upload it to the server. The uploaded file can be found in the images/files/c99.php.rar directory.

Mitigation:

Ensure that the server is configured to only allow the upload of legitimate files and that the uploaded files are scanned for malicious content.
Source

Exploit-DB raw data:

AJA Modules Rapidshare 1.0.0 Remote Shell Upload Vulnerability

______________________________

AUTHOR : Hussin X

Home   : WwW.IQ-TY.CoM   &  WwW.TrYaG.cc

Mail   : darkangel_G85@yahoo.com

______________________________


script : http://www.magtrb.com/en/modules.php?name=Downloads&op=getit&lid=6


________________________________

exploit :

1.

Change Type Shell from c99.Php to c99.php.rar


and go to

http://localhost/AJA/modules.php?name=Rapidshare


Browse , select your shell , and Click Enter


the uploaded file ( shell )  Will find it here


http://localhost/images/files/c99.php.rar


________________________________



Greetings  : all my friends  |  IQ-SecuritY   |  TrYaG   | Milw0rM

# milw0rm.com [2009-02-03]