Aplikasi Kartu Pelajar Vulnerability arbitrary file upload with CSRF(indonesian school)

2021.01.17
id Meicookies (ID) id
Risk: Medium
Local: No
Remote: Yes
CVE: N/A
CWE: N/A

[+]Exploit title: Aplikasi Kartu Pelajar Vulnerability arbitrary file upload with CSRF(indonesian school) [+]Author : ./meicookies [+]Dork : intext:Responsive image aplikasi kartu pelajar sch.id [+] Exploit: kartu.localcrot.sch.id/user/aksi/ubah_pelajar.php if there is an alert "Data Berhasil di Ubah" the fucking website is vulnerable to arbitrary file upload [+] CSRF : https://tools.xploitsecid.or.id/Exploit/CSRF postfile : gambar [!] File Location : The files you upload will go to kartu.localcrot.sch.id/img/your_backdoor.php #hacktheplanet:D


Vote for this issue:
100%
0%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top