|
|
|
|
Menu |
|
|
Home |
| |
|
Discussions |
| |
|
Tools |
| |
|
Affiliates |
| |
|
Content |
| |
|
Info |
| | |
|
|
|
|
|
User Info |
|
Membership:
Latest: MichaelSnaRe
New Today: 0
New Yesterday: 0
Overall: 9144
People Online:
Visitors: 77
Members: 0
Total: 77
|
|
|
|
|
|
Full disclosure |
|
|
|
|
|
|
|
|
|
IT Security and Insecurity Portal |
|
|
TYPO3 - How to upload a php file ? |
|
Posted: Sat Mar 14, 2009 9:36 pm |
|
|
brisk |
Advanced user |
|
|
Joined: Mar 07, 2009 |
Posts: 108 |
|
|
|
|
|
|
|
Hey there..
So i was wondering if anyone know how to get a php script on a site with only access to the mysql database and typo3 admin center. |
|
|
|
|
|
Re: TYPO3 - How to upload a php file ? |
|
Posted: Sat Mar 14, 2009 10:07 pm |
|
|
x3roconf_ |
Advanced user |
|
|
Joined: May 01, 2008 |
Posts: 101 |
|
|
|
|
|
|
|
brisk wrote: | Hey there..
So i was wondering if anyone know how to get a php script on a site with only access to the mysql database and typo3 admin center. |
It's very easy. You can upload files trough typo3 admin panel. You can't upload files with
.php extension but .phtml and php.jpg are allowed. |
|
|
|
|
|
Re: TYPO3 - How to upload a php file ? |
|
Posted: Sun Mar 15, 2009 3:18 am |
|
|
brisk |
Advanced user |
|
|
Joined: Mar 07, 2009 |
Posts: 108 |
|
|
|
|
|
|
|
x3roconf_ wrote: | brisk wrote: | Hey there..
So i was wondering if anyone know how to get a php script on a site with only access to the mysql database and typo3 admin center. |
It's very easy. You can upload files trough typo3 admin panel. You can't upload files with
.php extension but .phtml and php.jpg are allowed. |
erm...
If i upload .phtml file.. it will only show me source code ( php code is not being executed )
& php.jpg = Code: | 1: Extension of file name "o.php.jpg" was not allowed! |
|
|
|
|
|
|
Re: TYPO3 - How to upload a php file ? |
|
Posted: Sun Mar 15, 2009 11:56 am |
|
|
x3roconf_ |
Advanced user |
|
|
Joined: May 01, 2008 |
Posts: 101 |
|
|
|
|
|
|
|
brisk wrote: |
If i upload .phtml file.. it will only show me source code ( php code is not being executed )
& php.jpg = Code: | 1: Extension of file name "o.php.jpg" was not allowed! |
|
Well that's odd.. I have uploaded .php.jpg files using typo3 admin panel without any problems. Maybe your target is running newer version of typo3? (or admin has made some
restrictions) |
|
|
|
|
Posted: Sun Mar 15, 2009 1:53 pm |
|
|
Chb |
Valuable expert |
|
|
Joined: Jul 23, 2005 |
Posts: 206 |
Location: Germany |
|
|
|
|
|
|
In some cases you are able to create a content element of type "PHP script" (that's an extension). If so, you might be able to create a mini-shell. |
|
|
|
|
www.waraxe.us Forum Index -> General discussion
You cannot post new topics in this forum You cannot reply to topics in this forum You cannot edit your posts in this forum You cannot delete your posts in this forum You cannot vote in polls in this forum
|
All times are GMT
Page 1 of 1
|
|
|
Powered by phpBB © 2001-2008 phpBB Group
|
|
|
|
|
|
|