[] NeoSense

FlexPHPDirectory 0.0.1 - Authentication Bypass

Author: x0r
type: webapps
platform: php
port: 
date_added: 2008-12-28 
date_updated: 2017-01-23 
verified: 1 
codes: OSVDB-51303;CVE-2008-6750;OSVDB-51302;CVE-2008-6749 
tags: 
aliases:  
screenshot_url:  
application_url: http://www.exploit-db.comflexphpdiren.zip

#############################################
Autore: x0r
Email: andry2000@hotmail.it
Site: http://w00tz0ne.altervista.org/index.php
Cms: Flexphpdiren
Version: 0.0.1
Download: http://www.china-on-site.com/flexphpdir/
##############################################

Bug In \admin\usercheck.php 'n' \add.php

$sql = "select username,adminid from linkexadmin where
username='$checkuser' and password='$checkpass'";


Exploit:

Go to /[path]/admin/index.php
Put as username and password the following sql code: ' or '1=1

Shell Upload:

Exploit: \add.php upload your shell and after /photo/ to see your shell ^ ^

Greetz: I Miss You...

# milw0rm.com [2008-12-29]