Lucene search

K
securityvulnsSecurityvulnsSECURITYVULNS:DOC:13916
HistoryAug 17, 2006 - 12:00 a.m.

WikiWebWeaver 1.0 beta 2 Upload Shell Vulnerability

2006-08-1700:00:00
vulners.com
6

!!!WWW.SiBERSAVASCiLAR.COM!!!

Title : WikiWebWeaver 1.0 beta 2 Upload Shell Vulnerability


#Author: Crackers_Child

#cont@ct: [email protected]


Affected software description :

Application : WikiWebWeaver 1.0 beta 2

URL : http://wikiwebweaver-devel.teuwen.org:8080/wiki/index.php?l=FR&display=QuoiDeNeuf_FR



Exploit:

WikiWebWeaver 1.0 beta 2 Script Have Upload part and you can upload only gif,jpeg lol :D

but you can upload gif.php or psd.php

http://www.site.com/wiki_path/index.php?upload

we upload a .gif.php or others than our shell go

http://www.site.com/wiki_path/data/documents/ourshell.gif.php :)

you can test it

on http://www.digi-sight.com/wiki/index.php?upload

greets:

X_ALPEREN_X,Root_MOr And All Other Friends


--------------------------------- [ WWW.SiBERSAVASCiLAR.COM ] --------------------------------------