Sinisterly
How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking)
+--- Thread: How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? (/Thread-How-to-exploit-this-Vulnerability-WordPress-User-Photo-Component-Remote-File-Upload)



How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - fawkes027 - 09-20-2012

How to exploit this Vulnerability?

# Exploit Title: WordPress User Photo Component Remote File Upload Vulnerability
# Google Dork: inurl:"/wp-content/uploads/userphoto/"
http://www.exploit-db.com/exploits/16181/


How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - Anima Templi - 09-20-2012

It's very semilar or equals to uploading a shell to the website. The shell will then allow you to control the website and possible also the server.

Read about shell uploading and you will get it.

PS. Please make a smaller a smaller subject title next time.


RE: - Vaibs - 09-22-2012

(09-20-2012, 06:05 PM)fawkes027 Wrote: How to exploit this Vulnerability?

# Exploit Title: WordPress User Photo Component Remote File Upload Vulnerability
# Google Dork: inurl:"/wp-content/uploads/userphoto/"
http://www.exploit-db.com/exploits/16181/

That is the Dork to lfi vulnerable wp website where you get direct upload page to upload folder.This lfi exist in Wp websites using vulnerable wp plugin.


RE: - fawkes027 - 10-25-2012

(09-22-2012, 06:52 AM)Vaibs Wrote: That is the Dork to lfi vulnerable wp website where you get direct upload page to upload folder.This lfi exist in Wp websites using vulnerable wp plugin.
What to do exactly?


How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - unknownAttacker - 10-26-2012

read the description. you need to create fake gif headers and write your backdoor encoded as hex or binary. use hex editor. if you have no idea what I'm talking about, you need to learn some theory: read about binary and hexadecimal data representations, filetypes and how browser interprets them


RE: How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - dR.0xYw0Rm - 11-06-2013

With a little shell uploading knowledge you will be able to perform the attack. Keep in mind that targets vulnerable to Remote File Upload are very hard to find.


RE: How to exploit this Vulnerability: WordPress User Photo Component Remote File Upload? - knightserv - 11-10-2013

nice but,, more info please.