LFI to RCE via access_log injection

Malaysian Zen Cart Sites

iseng2 nyari web malay sebelum makan siang niy.. wkawkakwakwkak..

login : adminz
pass : wew

ato

login : ganteng
pass : qwerty


http://www.batunisan.com.my/admin/login.php

http://delcom.net.my/shop/admin/login.php

http://mumdreams.com.my/onlinebutik/admin/login.php

http://sandmanguitaronline.com/admin/login.php

http://mixandmatch.com.my/zencart/admin/login.php

http://www.masterschoice.com.my/store/admin/login.php

http://www.aimeily.com.my/shop/admin/login.php

http://www.4allbeauty.com.my/shop2/admin/login.php

http://www.eco-sports.com.my/shop/admin/login.php

http://cyclegarage.com.my/garage/v1.3.8/admin/login.php

http://grays.com.my/shop/admin/login.php

http://shopping.ofitech.com.my/admin/login.php

http://ziodex.com.my/store/admin/login.php

http://ezprint.com.my/admin/login.php

http://www.utamaflorist.com/admin/login.php

http://www.protonsonic.com.my/admin/login.php

http://jackrabbit.com.my/admin/login.php

Comments

Djuwana vip said…
wah ..hebat2....
Noge Jaya,,,,,,terus post yang kayak gnian ya kak....heheheh
ijin nyoba..
Djuwana vip said…
Lapor.......URLnya udah mati alias g isa di gunakan ....
evilc0de said…
huahuahuahuahua..
udah lama itu bug na pasti dah banyak yang dipatch. :))
p4rcom said…
ngahahhahhaha....keren ene si Nonong Gede..... :P
salam,
Bukan-Diriku