header-logo
Suggest Exploit
vendor:
RapidLeech Scripts
by:
H-SK33PY
7,5
CVSS
HIGH
Remote File Upload
N/A
CWE
Product Name: RapidLeech Scripts
Affected Version From: all versions
Affected Version To: all versions
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: Linux
2010

RapidLeech Scrits Remote File Upload ( upload shell php )

RapidLeech scripts are vulnerable to remote file upload. An attacker can upload a malicious file to the server by changing the name of the shell code to shell.php.001 or shell.php.00 and then accessing it via the URL http://site.com/0x14/shell.php.001 or http://site.com/0x14/shell.php.00

Mitigation:

Ensure that the server is configured to prevent remote file uploads.
Source

Exploit-DB raw data:

# Exploit Title: RapidLeech Scrits Remote File Upload ( upload shell php )                    
# Date: 21/07/2010                             
# Author: H-SK33PY                      
# Software Link: http://www.rapidleech.com/
# Version: all versions
# Google dork :intitle:"Rx08.ii36B.Rv"
# Platform / Tested on: linux
# Category: remote
# Code : N/A


   010101010101010101010101010101010101010101010101010101010    
   0                                                       0
   1  Iranian Datacoders Security Team 2010
   0                                                       0
   010101010101010101010101010101010101010101010101010101010

#BUG:#########################################################################

After find the site of rapidleecher script on this :

To Active For run this method change the name of shell code 

example : shell.php >>>>>>> to  shell.php.001  or  shell.php.00

After trasfer this 

you can run it in this Url :
http://site.com/0x14/shell.php.001

or

http://site.com/0x14/shell.php.00

#############################################################################
Website : http://www.datacoders.ir

Special Thanks to : ccC0d3rZzz & all iranian datacoders members

#############################################################################