SAS Hotel Management System - Arbitrary File Upload

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1057465 漏洞类型
发布时间 2009-02-17 更新时间 2009-02-17
CVE编号 N/A CNNVD-ID N/A
漏洞平台 ASP CVSS评分 N/A
|漏洞来源
https://www.exploit-db.com/exploits/8070
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
[~] SAS Hotel Management System Remote Shell Upload
[~]
[~] Demo: http://www.aebest.com/home/home.asp
[~] ----------------------------------------------------------
[~] home: yildirimordulari.com   if you wanna help you must register to my site and ı will do help to you  xD
[~]
[~] home: yildirimordulari.com   eger yardim istiyosan siteye uye olmalisin xD
[~]
[~] author: ZoRLu  msn: trt-turk@hotmail.com  
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] Date:17/02/09
[~]
[~] My Best Friend: Dr.LY0N
[~] -----------------------------------------------------------

add this code your shell:

GIF89a;

after you go here : http://www.yildirim.com/register_hotel.asp

select your photo but photo must be your shell.asp

after finished you register

your shell here: http://www.yildirim.com/upload_images/shell.asp

 
for demo:

here:  http://www.aebest.com/home/register_hotel.asp

shell: http://www.aebest.com/upload_images/z.asp

[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke & Dr.LY0N & z3h!r & HEAD_HUNTER and yildirimordulari.com all users
[~]
[~] yildirimordulari.com  &  experl.com & z0rlu.blogspot.com
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2009-02-17]