建站极客  
                        网络安全                          Exploit                          正文 
                     
                 
                
                    MFORUM 0.1a Arbitrary Add-Admin Vulnerability                 
                
                    所属分类:
                        网络安全  / Exploit                      
                    阅读数:
                        124 
                    
                        
                                 
                             收藏 0
                                 
                             赞 0
                                 
                             分享 
                    
                 
                
                    ================================================= 
  MFORUM 0.1a Arbitrary Add-Admin Vulnerability 
================================================= 
 
  ,--^----------,--------,-----,-------^--, 
  | |||||||||   `--------'     |          O .. CWH Underground Hacking Team .. 
  ` ---------------------------^----------| 
    `\_,-------, _________________________| 
      / XXXXXX /`|     / 
     / XXXXXX /  `\   / 
    / XXXXXX /\______( 
   / XXXXXX /            
  / XXXXXX / 
(________(              
  `------' 
 
AUTHOR : CWH Underground 
DATE   : 13 July 2008 
SITE   : cwh.citec.us 
 
 
################################################################################### 
APPLICATION : MFORUM 
VERSION     : 0.1a 
DOWNLOAD    : http://downloads.sourceforge.net/marcioforum/mforum.zip 
################################################################################### 
 
 
--- Add-Admin Exploit --- 
 
***magic_quotes_gpc = off*** 
 
------------- 
Description 
------------- 
 
    MFORUM 0.1a has Vulnerability to escalate user's privilege to administartor's privilege. 
That Vulnerable in "Control Panel - Edit your profile" (http://[Target]/[mforum_path]/usercp.php?mode=edit_profile) 
and you can injection code into various field (City, Interest, Email, Icq, msn, Yahoo Messenger). 
 
    This action will give your account can use Admin Control Panel (http://[Target]/[mforum_path]/admin/index.php) 
with Administrative's Privilege. 
 
----------------- 
Vulnerable Path 
----------------- 
[ ] http://[target]/[mforum_path]/usercp.php?mode=edit_profile 
 
-------------- 
Exploit code 
-------------- 
[ ] hacked", type="2 
 
 
##################################################################### 
Greetz      : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos 
Special Thx : asylu3, str0ke, citec.us, milw0rm.com 
#####################################################################
                                     
             
            
                
                MyBulletinBoard (MyBB) <?php
// forum mybb <= 1.2.11 remote sql injection vulnerability
// bug found by Janek Vind "waraxe" http://www.waraxe
                    评论 0 
                    
                         
                     收藏 0
                         
                     赞 0
                         
                     分享
                 查看更多