#################################################################################################
# Exploit Title : WordPress Design By SmartCatDesign.Net ImageManager Plugin Remote File Upload Vulnerability
# Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
# Date : 23/06/2018
# Vendor Homepage : smartcatdesign.net
# Tested On : Windows
# Category : WebApps
# Exploit Risk : Medium
# CWE : CWE-264 [ Permissions, Privileges, and Access Controls ]
#################################################################################################
# Google Dorks :
intext:''Design By Smartcat''
intext:''Karma Theme - Designed by SmartCat''
# Exploit : /wp-content/plugins/ImageManager/manager.php
# PATH : /wp-content/uploads/[yourfilename.png]
# Note [ Very small size picture ] => /wp-content/uploads/.thumbs/.[yourfilename.png]
# Create a New Folder in the WordPress ImageManager => /wp-content/plugins/ImageManager/newfolder.php
# PATH : /wp-content/uploads/[CREATED-FOLDER]/[yourfilename.png]
# Note : Allowed File Extensions : .gif .jpg .jpeg .png
# Note : An attacker can delete created folders in the ImageManager Plugin.
#################################################################################################
# Example Site : magicrelationship.net/blog/wp-content/plugins/ImageManager/manager.php
# Proof of Concept for this Vulnerability : archive.is/DRb4j ~ archive.is/48DC4
#################################################################################################
# Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
#################################################################################################