|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 66
Members: 0
Total: 66
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
|
Warning: Missing argument 1 for forward() in /home/web/functions/forward.php on line 3
Warning: Cannot modify header information - headers already sent by (output started at /home/web/functions/for ... |
|
|
|
|
http://www.example.com/phpnuke/admin.php?op=deladmin2&del_aid=dudul
dudul = original admin nick |
|
|
|
|
i need the name of the all modules php-nuke |
|
|
|
|
//config.php
...
// We don't like magic_quotes
no_magic_quotes();
...
//end |
|
|
|
|
http://www.appointment-plus.com/ap_admin/admin.php
Warning: Supplied argument is not a valid MySQL result resource in /home/www/appointment-plus/ap_admin/admin.php on line 58
i try sql injection ... |
|
|
|
|
working...........
admin.php?admin=eCcgT1IvKjp5
then we have blank screen with short message: "die". Hmm, wtf?
but.......
http://localhost/nuke71/admin.php?foo=bar&admin=eCcgT1IvKjp5
... |
|
|
|
|
good,.......................................... |
|
|
|
|
SQL Injection:
http://[target]/nuke73/modules...amp;rop=Q&order=[Malicious Code]
[target]= www.target.com
[nuke73]=subfolder...?
[malicious code]= JS or...?
[modules...amp]=
sorry :r ... |
|
|
|
|
http://[target]:2086/scripts/killacct?domain=(domain)&user=(user)&submit-domain=Terminate
domain=[?]
user=[?]
?=[injection]
this is correct....? |
|
|
|
|
Proof Of Concept:
http:// |
|
|
Page 1 of 1 |
All times are GMT |
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|