========================================================================
| # Title : Social Directory Script 2.0 File Upload vulnerability
| # Author : indoushka
| # email : indoushka4ever@gmail.com
| # Tested on : windows 8.1 Français V.(Pro)
| # Version : 2.0
| # Vendor : http://www.phponly.com/
| # Dork : "Copyright poSocial Directory"
========================================================================
poc :
1 - Register on the script and choose a file in any extension you want and complete the registration
http://www.phponly.com/demo/link/register.php
2 - Go to and through the attachments you find the uploaded file
http://www.phponly.com/demo/link/userprofile.php
Greetz : ===============================================================
|
jericho * Larry W. Cashdollar * moncet-1 * Gjoko Krstic |
|
========================================================================