[ authorization ] [ registration ] [ Restaurer ]
Contactez nous
Vous pouvez nous contacter par:
0day.today   marche d

Vanilla Forums 2.0.18.7 Remote Code Execution Exploit

[ 0Day-ID-27860 ]
Titre complet
Vanilla Forums 2.0.18.7 Remote Code Execution Exploit [ Highlight ]
Highlight - is paid service, that can help to get more visitors to your material.

Price:
Date d'ajout
Catégorie
Plateforme
Vérifié
Prix
 
0.002 BTC

 
99 USD
Risque
[
Security Risk Critical
]
Rel. releases
Description
Vanilla Forums >= 2.0.18.7 RCE shell injector
inject a simple php eval() shell into target that can be used for further exploitation.
Info d'utilisation
usage:
first, inject the shell:
python inject_shell.py -a http://www.attacksite.com/forumsubdomain
after injecting the shell you can also inject your own pages or webshells:
python inject_shell.py -p http://www.attacksite.com/forumsubdomain page_to_inject.php


Send commands using http://www.attacksite.com/rprc.php?0=yourcommand
example: http://www.attacksite.com/rprc.php?0=echo('IT WORKS!');
Editeur
vanillaforums.com
Version affectée
<= 2.0.18.7
Testé sur
Windows xp, Windows 7, Windows 10, Xampp, Lampp, Ubuntu Linux, Apache.
Solution
update
CVE
CVE-2013-3527
Tag
Vanilla   forums   2.0   2.0.18.7   exploit   RCE   remote   shell   injector   2.0.18  
Other Information
Abuses
2
Commentaires
3
Vue
9 782
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
Please login or register to buy exploit.
OR
Buy incognito
0
0
Verified by
Verified by
This material is checked by Administration and absolutely workable.
Learn more about    GOLD:
0day.today Gold is the currency of 0day.today project and is denoted on this site as such image: . It used for paying for the services, buying exploits, earning money, etc
nous acceptons:
BitCoin (BTC)
You can pay us via BTC
LiteCoin (LTC)
You can pay us via LTC
Ethereum (ETH)
You can pay us via ETH

BL
29
Exploits
1
Lecteurs
0

Identifiez-vous ou inscrivez-vous pour laisser un commentaire

[ Commentaires: 3 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.

Identifiez-vous ou inscrivez-vous pour laisser un commentaire