[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Easy File Uploader - Arbitrary File Upload Vulnerability

Author
Daniel Godoy
Risk
[
Security Risk High
]
0day-ID
0day-ID-27690
Category
web applications
Date add
27-04-2017
Platform
php
# Exploit Title: Easy File Uploader  - Arbitrary File Upload
# Date: 27/04/2017
# Exploit Author: Daniel Godoy
# Vendor Homepage: https://codecanyon.net/
# Software Link: https://codecanyon.net/item/easy-file-uploader-php-multiple-uploader-with-file-manager/17222287
# Tested on: GNU/Linux
# GREETZ: Rodrigo Mouriño, Rodrigo Avila, #RemoteExecution Team
 
 
POC
 
Drop file php (shell.php) to upload.
access to http://poc_site/fileFolder/shell.php and enjoy!

#  0day.today [2024-11-16]  #