Simple Help Desk Remote Upload Vulnerability



EKU-ID: 1893 CVE: OSVDB-ID:
Author: L3b-r1'z Published: 2012-04-11 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#########
# Author : L3b-r1'z
# Title : Simple Help Desk Remote Upload Vulnerability
# Email : L3br1z@gmail.com
# Site : Sec4Leb.Com
# Download : http://simplehelpdesk.com/helpdeskfinal.zip
# Dork : allintitle: "Help Desk - Log In"
#########


  # # #           # # #     # #                                           # #                   
    #           #       #     #                                             #                   
    #                   #     #   # #                     # #   # #         #         # # # # # 
    #               # #       # #     #     # # # # #       # #             #         #     #   
    #     #             #     #       #                     #               #             #     
    #     #     #       #     #       #                     #               #           #     # 
  # # # # #       # # #     # # # # #                     # # # #       # # # # #     # # # # # 



Upload Vuln

[+] P0c :

First Register In Site , and Go To Add Tickets , Then Upload Your Shell .

Snap :

http://www11.0zz0.com/2012/04/10/02/528028598.png

You Will Find shell Here :

Http://domain.tld/attachments/Md5.php

Your Shell Name Will Encrypted MD5 , Upload Your Shell Like : 1.php , And Encrypt Your Name Shell (1) .

And Browse It Like : http://www.Domain.TLD/Attachments/40ed299be64fc353ebeedf37623ad84f.php

Example Shell :

http://www.buypixelscript.com/support/attachments/40ed299be64fc353ebeedf37623ad84f.php

And More In Google :)

./EOE

Note : Fuck To All the Lamer'z .