Image1

Friday, 10 February 2012

SimogeoFilemanager Upload File Vulnerability ...( Upload Your Shell )



Hey frenzz,
Today i ws lookin 4 a new vulnerability n find out this vulnerability. original advisory for this post is 1337day.
Auther of this Exploit is RoxSecurityTeam.





I brought this post for EDUCATIONAL purpose not for misuse or illegal ways of Hacking...


WARNING: I am not reponsible of any harm with this methods. ....Do it at your own risk..


Google Dorks: 
inurl:/filemanager/userfiles/ 
filetype:pdf 
inurl:/filemanager/index.html
Steps:

1.Search site that contains the vulnnerable file /filemanager/index.html
2.Upload Backdoor Shell.php
3.Move to the folder where files are stored /UserFiles/ Exemple: http://site.com/filemanager/UserFiles/Shell.php
4.you can have full access to your shell
Demonstration :
http://www.comune.gattinara.vc.it/newSys/ckeditor/filemanager/index.html
ftp://193.9.21.135/riba.si/wwwroot/cms/controls/ckeditor/filemanager/index.html
njoy ;)

Filled Under:

0 comments:

Post a Comment