lo0.ro cat /dev/null > stupidity – nobody is safe

28May/111

cPanel < 11.25 CSRF – upload shell CRSF

Nice news:

cPanel versions below and excluding 11.25 , are vulnerable to CSRF which
leads to uploading a PHP script of the attackers liking. If you have turned
off security tokens and referrer security check, no matter what version you
are using, you are vulnerable as well.

Proof of concept (PoC)

 

[cc lang="html"]

value="">


 

[/cc]

Afterwards simply check for ninjashell.php in the directory.

Source

Author: You can always email me ninjashellmail a|t gmail |c|om or follow me on twitter
@ninjashell1337

  • Google Reader
  • Facebook
  • Identi.ca
  • Twitter
  • Reddit
  • Delicious
  • E-Mail
  • StumbleUpon
  • Digg
  • Tumblr
Comments (1) Trackbacks (0)
  1. Hello sir.
    Nice to meet you sir i want to know how to upload shell into cpanel and how to hack cpanel +shell help me sir Thanks

    Best regard


Leave a comment

No trackbacks yet.