|
Best Top List Remote File Upload Vulnerability
----------------------------------------------
Script : Best Top List
Version : All Version
Site : http://besttoplist.sourceforge.net (Closed)
Founder : Rizgar
Contact : rizgar@linuxmail.org and irc.gigachat.net #kurdhack
Thanks : KHC, PH , ColdHackers
d0rk : "Powered by Best Top List by Szymon Kosok v. 2.11" inurl:"banner-upload.php" "Copyright (c) 2002 - Best-Scripts.TK"
----------------------------------------------
Vulnerability details ;
Best Top List contains a vulnerability that allows remote attackers to upload arbitrary files to any directory in the system. This bug is effective in the link "banner-upload.php." Do you neccessary a phpshell script in the upload server. Your files you loaded the genarally ; www.site.com/banners/shell.php in see
POC :
http://www.site.com/path/banner-upload.php
-----------------------------------------------------------
Code god ready in one simple shape.;
> cat banner-upload.php
echo "
>>>>>> see :]
";
include "footer.php";
?>