Author : Gaddar
Team : SiyahBayrak
Vulnerability Title : Element Ajans Scripts Local File Inclusion Vulnerability
Vendor HomePage : https://www.elementajans.com/
Date : 22 Feb. 2020
Dorks
intext:Copyrigt © 2019 Element Ajans ®
PoC;
Add payload url for script websites.
Paste shell urls.
Remote shells :)
Root server or hack :)
Payload : index.php?sayfa=iletisim
Code
<?php
include($_GET['iletisim.php'])
?>
Demo
https://www.mevlanareklam.com.tr/index.php?sayfa=iletisim