Login Register
The stories and information posted here are artistic works of fiction and falsehood. Only a fool would take anything posted here as fact.


How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? filter_list
Author
Message
How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? #1
How to exploit this Vulnerability?

# Exploit Title: WordPress User Photo Component Remote File Upload Vulnerability
# Google Dork: inurl:"/wp-content/uploads/userphoto/"
http://www.exploit-db.com/exploits/16181/


How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? #2
It's very semilar or equals to uploading a shell to the website. The shell will then allow you to control the website and possible also the server.

Read about shell uploading and you will get it.

PS. Please make a smaller a smaller subject title next time.


RE: #3
(09-20-2012, 06:05 PM)fawkes027 Wrote: How to exploit this Vulnerability?

# Exploit Title: WordPress User Photo Component Remote File Upload Vulnerability
# Google Dork: inurl:"/wp-content/uploads/userphoto/"
http://www.exploit-db.com/exploits/16181/

That is the Dork to lfi vulnerable wp website where you get direct upload page to upload folder.This lfi exist in Wp websites using vulnerable wp plugin.


RE: #4
(09-22-2012, 06:52 AM)Vaibs Wrote: That is the Dork to lfi vulnerable wp website where you get direct upload page to upload folder.This lfi exist in Wp websites using vulnerable wp plugin.
What to do exactly?


How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? #5
read the description. you need to create fake gif headers and write your backdoor encoded as hex or binary. use hex editor. if you have no idea what I'm talking about, you need to learn some theory: read about binary and hexadecimal data representations, filetypes and how browser interprets them


RE: How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? #6
With a little shell uploading knowledge you will be able to perform the attack. Keep in mind that targets vulnerable to Remote File Upload are very hard to find.
If you need help , drop me a PM and I will help you with the best I can !

[Image: V7mYdF6.png]




RE: How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? #7
nice but,, more info please.








Users browsing this thread: 1 Guest(s)