Thursday, August 30, 2012

DiyWeb Admin Bypass and Remote file/shell Upload exploit


Exploit title : DiyWeb Admin Bypass and & file Upload exploit
Discovered By : NoentryPhc
Sever : windows
Type : web application
Shell extention : .asp

Dork : "Power by DiyWeb"
            inurl:/template.asp?menuid=
Poc : diyweb/menu/admin/image_manager.asp
This exploit's almost all vulnerable websites are Malaysiyan.
To upload your files Goto : http://www.website.com/diyweb/menu/admin/image_manager.asp

and upload your shell/deface there !
if .php extention is not allowed then your can try tamper data and live http headers
to acess your file goto : http://www.website.com/Images/yourfilehere and sometimes you have to find your manually on websites
Link:http://www.famosapadu.com.my/images/index.html

6 comments:

  1. I opened with this Nerotenze strategy. I have this overpowering compulsion on those times. I got that for a song. We have way too little Nerotenze. Dynamite! This is how to manage your Nerotenze testosterone. You just may discover that by learning as this touches on Nerotenze. I have a three ring binder in connection with Nerotenze to be commonplace. Embed this in your thought process: Nerotenze is very complex. For a fact, Nerotenze has done far less good than good to Nerotenze. Every morning is a beginning with Nerotenze. It's not different than getting Nerotenze. That will be a bizarre twist. >>https://www.healthstrikes.com/nerotenze-testosterone/

    ReplyDelete
  2. Slim Tone a perfect blend of natural components is a dietary weight loss supplement that helps to get your body reshaped by shedding unwanted body fat easily and effectively. The stored body fats are trimmed up and reduced as energy to the body and finally makes you slim within weeks. Visit on Slimtone Keto Weight Loss Supplement

    ReplyDelete
  3. I know a hacker who can help you spy on your cheating boyfriend's / girlfriend's / spouse phone, whatsapp, facebook, or other platforms just contact  brillianthckers800@gmail.com, he is the best out there, he is a professional, trustworthy hacker, he helped reveal my ex wife's secret affairs, he also helped settle bank loans, thanks to him I am now a free man, contact him and he will leave you happy then you can thank me later.

    ReplyDelete
  4. i was lost with no hope for my wife was cheating and had always got away with it because i did not know how or always too scared to pin anything on her. with the help a friend IN PERSON OFJOHN who recommended me to who help hack her phone, email, chat, sms and expose her for a cheater she is. I just want to say a big thank you to HACKINTECHNOLOGY@GMAIL.COM . am sure someone out there is looking for how to solve his relationship problems, you can also contact him for all sorts of hacking job..he is fast and reliable. you could also text +1 669 225 2253

    ReplyDelete
  5. I'm sure I am not the only one who knows the most reliable Recovery Agency. I see a lot of recommendations online and it’s already obvious there are bad eggs online who will only add to your mystery. The best thing that happened to me this month is coming across a reliable Recovery Agency. Geo Coordinates Hacker, a professional hacker and private investigator. I had invested $97,000 into a cryptocurrency platform that turned out to be a scam and I had no idea how to get back my money until someone recommended me to Geo Coordinates Hacker. I contacted them, and they were able to recover everything from these scammers without breaking a sweat. I’m truly grateful and I’m sharing this out there with everyone. You might have been involved in a romance scam, or fake cryptocurrency investment, and you wish to get back your money, then you need to contact Geo Coordinates Hacker too. Don’t let anyone get away with your hard-earned money. This is their Email Address: (geocoordinateshacker@proton.me.)
    (geovcoordinateshacker@gmail.com)

    ReplyDelete