# Title : Wordpress gallery-bank Plugin Upload Vulnerability
# Severity : High+/Critical
# Reporter(s) : Mohit Amn Security Team (Shahab Shamsi)
# Google Dork : inurl:"/wp-content/plugins/gallery-bank/" "upload.php"
# Plugin Name : gallery-bank
# Plugin Download Link : https://downloads.wordpress.org/plugin/gallery-bank.zip
# Vendor Home : http://werdswords.com/
# Date : 25/08/2014
# Tested in : Linux
# Video Link : http://youtu.be/2Y0ZiTdX-o8
# PoC :
# Target.com/wp-content/plugins/gallery-bank/patch/upload.php
# - upload shell