<tr>

</table>

</form>";
include "footer.php";

Pantek Library
Hosting Provided By
CybrHost
High Speed Hosting

Best Top List Remote File Upload Vulnerability

From: <rizgar(at)linuxmail.org>
Date: Sat Aug 11 2007 - 12:51:00 EDT


Best Top List Remote File Upload Vulnerability


Script : Best Top List

Version : All Version

Site : http://besttoplist.sourceforge.net (Closed)

Founder : Rizgar

Contact : rizgar@linuxmail.org and irc.gigachat.net #kurdhack

Thanks : KHC, PH , ColdHackers

d0rk : "Powered by Best Top List by Szymon Kosok v. 2.11" inurl:"banner-upload.php" "Copyright (c) 2002 - Best-Scripts.TK"


Do you need help?X

Vulnerability details ;

Best Top List contains a vulnerability that allows remote attackers to upload arbitrary files to any directory in the system. This bug is effective in the link "banner-upload.php." Do you neccessary a phpshell script in the upload server. Your files you loaded the genarally ; www.site.com/banners/shell.php in see

POC : http://www.site.com/path/banner-upload.php


Code god ready in one simple shape.;

> cat banner-upload.php

echo "<br><br><center>" . $lang['uploadtxt'] . "<br><br> >>>>>> see :]

<form enctype='multipart/form-data' method='post' action='upload.php'>

<input type='hidden' name='action' value='upload'>

Do you need more help?X

<table frame=box rules=none border=0 cellpadding=2

       cellspacing=0 align='center'>

   <tr>

<td>Banner:</td>

<td><input type='file' name='userfile'></td>

   </tr>

<tr>

<td>" . $lang['siteurlwohttp'] . ":</td>

Can we help you?X

<td><input type='input' name='sitename'></td>

   </tr>

   <tr>

<td></td>

<td><input type='submit' name ='upload'

                 value='Upload'>
Can't find what you're looking for?X

?> Received on Mon Aug 13 10:56:09 2007

This archive was generated by hypermail 2.1.8 : Sun Oct 28 2007 - 06:11:29 EDT

Contact Us  Legal Notices  Order Services Online 
Pantek Home  Privacy Policy  IT news  Site Map  Pantek Library