header-logo
Suggest Exploit
vendor:
by:
Mr.Benladen
N/A
CVSS
N/A
Remote Upload
CWE
Product Name:
Affected Version From: 2004
Affected Version To: 2008
Patch Exists: NO
Related CWE:
CPE:
Metasploit:
Other Scripts:
Platforms Tested: Linux/Unix
2010

greeting card Remote Upload Vulnerability

The exploit allows remote upload of files through a greeting card website. After registering on the website and uploading shells, the uploaded files can be accessed at http://[site]//cards/id_thumb_evil.php. An example demo URL is http://server/cards/1275663706_thumb_oujda.php.

Mitigation:

Unknown
Source

Exploit-DB raw data:

# Exploit Title: [greeting card Remote Upload Vulnerability]
# Date: [04/06/2010]
# Author: [Mr.Benladen]
# Software Link: [N/A]
# Version: [2004/2008]
# Tested on: [Linux/unix]
# CVE : [if exists]
# Code : [N/A]
#Email : MaFiadu48@hotmail.fr

##############################
########################################################################

# # # #
# # # #
# # # #
# ## #### ## #
## ## ###### ## ##
## ## ###### ## ##
## ## #### ## ##
### ############ ###
########################
Mr.Benladen cr3w
##############
######## ########## #######
### ## ########## ## ###
### ## ########## ## ###
### # ########## # ###
### ## ######## ## ###
## # ###### # ##
## # #### # ##
## ##

######################################################################################################

[Dork ]: "Send amazing greetings to your friends and relative!"

{exploit} : http://127.0.0.1/upload.php

First register and the site and go to upload cards

After you have uploaded your shells , you will find it in this Path :
http://[site]//cards/id_thumb_evil.php

demo : http://server/cards/1275663706_thumb_oujda.php

######################################################################################################


Greetz To : Federal7-blackroot-khalidmoro-ra3ch-yesmouh-Zi00n From
Ukrania-Dr.Prorat all My Friend

and al muslim h4x0r

M0r0Can Is Here

--=-=-=-=-www.Joomlaservice.info <http://www.joomlaservice.info/> or
www.dz4all.com -=-=-=-=--=