***************************************************
# Exploit Title: Lokomedia CMS Arbitrary File Upload
# Google Dork: intitle:..::: Login User :::.. "Pegawai yang belum"
# Date: 04/07/2018
# Author: 0N3R1D3R
# Team: Error Violence
# Tested on: Windows 10 x64
***************************************************
[+] Save this csrf in html ( https://pastebin.com/raw/50BWjtuz )
[+] Search the dork in Google
[+] Change form action with your target
[+] Complete the form and up your backdoor ( Sometimes the backdoor should be bypassed )
[+] Login with username and password 1
[+] Copy image address and remove small_ for access your backdoor
***************************************************
[+] Demo Site
[+] http://pegawai.ibmb.ac.id/
[+] https://www.pegawai.apikescm.ac.id/
[+] http://staffsite-hukum.umpwr.ac.id/
***************************************************
Thanks To Error Violence