more c00l wayz to upload ur shell

c0rrupter

V.I.P
V.I.P
Joined
11 yrs. 6 mth. 30 days
Messages
1,914
Reaction score
3,194
Age
31
Wallet
0$
Here we will be using Tiny MCE Ajax File Manager to upload our shell.

TinyMCE AjaxFileManager Shell Upload is a vulnerability in TinyMCE which allows simple upload of .txt .jpg .png .jpeg .bmp and in some cases even allows us to upload PHP shell or a deface page.

The Dork: inurl:/tiny_mce/plugins/filemanager/
The dork will bring up this image.
946256699d6f99c7d603abf39b9bf85b.png




This is the exploit

http://[localhost]/[path]/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php

http://[localhost]/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php


Navigate to any of the above links (any one of them will be present) and check the top right corner, you will see a upload option there. Click on it, select your file and click on upload.


To view your uploaded file visit
Please, Log in or Register to view URLs content!


Good luck. Have fun. Make babies.
 
Paid adv. expire in 2 months
CLICK to buy Advertisement !
westernunion carding Verified & Trusted WesternUnion | MoneyGram | Bank - Transferring [299$ BTC for 2000$ WU]
electronics carding Verified & Trusted Electronics Carding, Carding iPhone, Samsung Carding, MacBook Carding, Laptops Carding

M33

[ Verified Seller ]
Staff member
Trusted Seller
Joined
11 yrs. 8 mth. 23 days
Messages
5,010
Reaction score
11,818
Wallet
13,191$
does it upload .php files?
 
Top Bottom