Monday, June 30, 2014

Remote File Inclusion [RFI] Dorks




/components/com_flyspray/startdown.php?file=
/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=
/components/com_simpleboard/file_upload.php?sbp=
/components/com_hashcash/server.php?mosConfig_absolute_path=
/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=
/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=
/components/com_performs/performs.php?mosConfig_absolute_path=
/components/com_forum/download.php?phpbb_root_path=
/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=
/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=
/components/minibb/index.php?absolute_path=
/components/com_smf/smf.php?mosConfig_absolute_path=
/modules/mod_calendar.php?absolute_path=
/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=
/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=

Exploit Wordpress : fbconnect SQL Injection Vulnerability

Dork:
inurl:"fbconnect_action=myhome"

Exploit: 

Shop737 - File Upload Vulnerabilities

Finding Vulnerable Target

Dork:
intext:"Powered by Shop737"

1- Copy and paste this dork on Google.

2- Choose any site as your target.

3- Once you clicked on your target, you will see something like this,




Exploit Elfinder - Shell Upload Vulnerability



Dork:
                        inurl:'elfinder.php.html'
inurl:'elfinder.html'

Sunday, June 29, 2014

Moxiecode File Browser - An Uploading Vulnerability

Hi guys, I'm the new guy has just come to this blog :) This will be my first post on this blog...

An uploading vulnerability that you can upload files :)