AvailScript Classmate Script - Arbitrary File Upload

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057027 漏洞类型
发布时间 2008-12-14 更新时间 2008-12-14
CVE编号 N/A CNNVD-ID N/A
漏洞平台 PHP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/7457
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
[~] Availscript Classmate Script Remote File Upload Vulnerability
[~]
[~] ----------------------------------------------------------
[~] Discovered By: S.W.A.T.   svvateam@yahoo.com
[~]
[~] Home: www.batlagh.com
[~]
[~] Script Page: http://www.availscript.com/classmate_script.php
[~] -----------------------------------------------------------

Xpl:

1.First Register Into The Site ( link: www.site.com/[path]/register.php )

2.In Register Section Select Your phpshell like: c99.php

3.In "Latest Members" Section Right Click On Blank Line & Then Choose Properties

4.Copy The Link Of Your Shell Like: http://www.availscript.com/classmate/memberspics/saeid-61609-c99.php

5.Your Shell Will Be Renamed With Your Name & Random ID like: saeid-61609-c99.php

6.Hack The Site ;)


Demo:

http://www.availscript.com/classmate/



[~] Special Thanks To:

Str0ke, All My Friends, Iranian Hackers & All Muslim

# milw0rm.com [2008-12-14]