ImageUploader Vulnerable

2020-04-22 / 2020-04-21
id Nirwana (ID) id
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

[+] Title: ImageUploader Vulnerable [+] Date: 2020-04-22 [+] Author: Nirwana [+] Team : Indramayu HackerLink [+] Tested on: Windows 10 & Google Chrome [+] Version : All Versions [+] Category : Web Application Bugs [+] Vulnerable File: /imgbrowser.php [+} Dork : index of /plugins/ckeditor/plugins/imageuploader/ If asked to enter a username / password Just put User: admin Pw: admin

References:

Web Demo :
https://seken.co.id/assets/js/plugins/ckeditor/plugins/imageuploader/imgupload.php
https://www.hcitysawangan.com/assets/backoffice/js/ckeditor/plugins/imageuploader/imgbrowser.php
Thanks To : Nirwana , A666H4k0R, EXID


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top