The
Exploit url will be like this
http://[site]/../../js/tiny_mce/plugins/filemanager/upload.php
or
http://[site]/../../js/tiny_mce/plugins/filemanager/upload.php
or
http://[site]/
tiny_mce/plugins/filemanager/filelist.php
Live Demo:
To upload files
Click
on “upload new file” icon on the top of page it is located in left corner at
the top.
After
clicking on Upload new file icon you'll see a new pop up for upload new files
To Preview your uploaded file, then go to : [site].com/images/urfile if you uploaded an image
and if you have uploded .html file see it here
site.com/files/deface.html
or
http://[site]/../../js/tiny_mce/plugins/filemanager/files/deface.html
You Might Also Like
0 comments:
Post a Comment