标签:&039
-
PHPCMS2.4中一个有趣的洞洞”
今天,朋友丢来一个站,说想拿点资料,但搞了很久老搞不下,叫我帮忙看看打开一看发现是phpcms2.4,很旧的版本了~~搞了一下发现存在“上传漏洞”和“远程文件包含漏洞”的页面都被删了,晕,自己挖个把,反正版本旧挖了1个多小时,发现vote.php中有这样一段代码...
-
PunBB口令重置弱随机数绕过安全限制漏洞”
PunBB是一款基于PHP的论坛程序。PunBB的口令重置功能实现上存在漏洞,远程攻击者可能利用此漏洞在特定条件重置用户的口令。如果用户忘记了口令的话,可使用PunBB的口令重置功能重置。在请求口令重置后,论坛会向用户发送一封邮件,包含有一个新的随机口令以及激...
-
Oracle 10g KUPM$MCP.MAIN SQL Injection Exploit”
#!/usr/bin/perl # # Remote Oracle KUPM$MCP.MAIN exploit (10g) # # Grant or revoke dba permission to unprivileged user # # Tested on "Oracle Database 10g Enterprise Edition Release 10.1.0.3.0" # # REF: http://www...
-
PHPizabi 0.848b C1 HFP1 Remote Code Execution Exploit”
#!/usr/bin/perl #inphex#PHPizabi v0.848b C1 HFP1 Remote Code Execution#http://www.dz-secure.com/tools/1/WebESploit.pl.txt#if you are seeking for a partner to work on some project(s) just send an email inphex0 [ at ] gmail [ dot ] com#s...
-
NaviCOPA Web Server 2.01 Remote Buffer Overflow Exploit (meta)”
## # This file is part of the Metasploit Framework and may be redistributed # according to the licenses defined in the Authors field below. In the # case of an unknown or missing license, this file defaults to the same # license as the co...
-
Quicksilver Forums 1.4.1 forums[] Remote SQL Injection Exploit”
<?php/*. vuln.: Quicksilver Forums 1.4.1 (forums[]) Remote SQL Injection Exploit. download: http://www.quicksilverforums.com/.. author: irk4z[at]yahoo.pl. homepage: http://irk4z.wordpress.com/.. greets: all friends ;)....
-
Document Imaging SDK 10.95 ActiveX Buffer Overflow PoC”
<!--Document Imaging SDK Buffer Overflow Vulnerability DoS Proof of conceptAuthor: r0ut3rMail : writ3r [at] gmail.com------------------------------Tested on WinXP Pro SP2Version: 10.95Vendor :...
-
安全检测ASP.net开发网站实例”
今天上了一个人才招聘网站,对他们的招聘系统我很感兴趣,aspx结尾的,看来是.net的程序,这样的网站会不会有什么漏洞呢?顺便打开一条消息 http://www.cnwill.com/NewsShow.aspx?id=4847 ,然后加一个' 看看出现什么?我晕。。Source: .Net SqlClient Data Provi...