exploit the possibilities
Home Files News &[SERVICES_TAB]About Contact Add New

Nuked Klan CMS 1.8 File Upload

Nuked Klan CMS 1.8 File Upload
Posted Jan 9, 2017
Authored by M.R.S.L.Y

Nuked Klan CMS version 1.8 suffers from a remote file upload vulnerability.

tags | exploit, remote, file upload
SHA-256 | 2a8059fbc9afba36b25b2f06187c21d3fc67549177e11620eb63da0ccdb09356

Nuked Klan CMS 1.8 File Upload

Change Mirror Download

*=============================================================|
|A Exploit Title:A CMS_Nuked-Kla File Upload Vulnerability
|
|A Exploit Author: Ashiyane Digital Security Team
|
|A Vendor HomePage: https://github.com/Nuked-Klan/CMS_Nuked-Klan
|
|A Download Link : https://github.com/Nuked-Klan/CMS_Nuked-Klan/archive/develop_1.8.zip
|
|A Version : V 1.8
|
|A Dork : index of:"filemanager/dialog.php"
|
|A Tested on:A Kali Linux
|
|A Date: 1 /3 / 2017
*=============================================================|
|A Vulnerability Path : http://127.0.0.1/CMS_Nuked-Klan-develop_1.8/media/tinymce/plugins/filemanager/dialog.php
|A Vulnerability Path : http://127.0.0.1/6/CMS_Nuked-Klan-develop_1.8/media/filemanager/dialog.php
|A Vulnerability Method :GET
*===========================|
|A Proof :
|
|A http://arksun.com/plugins/tinymce/filemanager/dialog.php
|A https://www.mygolfballdrop.com/static/plugins/filemanager/dialog.php
|A http://www.globalasset-group.com/wwwassets/libraries/filemanager/dialog.php
|A http://www.gracegospelcommission.org/filemanager/dialog.php
|A http://www.visiun.fr/lib/filemanager/dialog.php
*===========================|
|A Vulnerability description
*===:
|A This page allows visitors to upload files to the server.
|A Various web applications allow users to upload files (such as images, html, ...).
|A Uploaded files may pose a significant risk if not handled correctly.
|A A remote attacker could send a multipart/form-data POST request
|A with a specially-crafted filename or mime type and execute arbitrary code.
*=============================================================|
| Discovered By : M.R.S.L.Y
*=============================================================|A
Login or Register to add favorites

File Archive:

April 2024

  • Su
  • Mo
  • Tu
  • We
  • Th
  • Fr
  • Sa
  • 1
    Apr 1st
    10 Files
  • 2
    Apr 2nd
    26 Files
  • 3
    Apr 3rd
    40 Files
  • 4
    Apr 4th
    6 Files
  • 5
    Apr 5th
    26 Files
  • 6
    Apr 6th
    0 Files
  • 7
    Apr 7th
    0 Files
  • 8
    Apr 8th
    22 Files
  • 9
    Apr 9th
    14 Files
  • 10
    Apr 10th
    10 Files
  • 11
    Apr 11th
    13 Files
  • 12
    Apr 12th
    14 Files
  • 13
    Apr 13th
    0 Files
  • 14
    Apr 14th
    0 Files
  • 15
    Apr 15th
    30 Files
  • 16
    Apr 16th
    10 Files
  • 17
    Apr 17th
    22 Files
  • 18
    Apr 18th
    45 Files
  • 19
    Apr 19th
    0 Files
  • 20
    Apr 20th
    0 Files
  • 21
    Apr 21st
    0 Files
  • 22
    Apr 22nd
    0 Files
  • 23
    Apr 23rd
    0 Files
  • 24
    Apr 24th
    0 Files
  • 25
    Apr 25th
    0 Files
  • 26
    Apr 26th
    0 Files
  • 27
    Apr 27th
    0 Files
  • 28
    Apr 28th
    0 Files
  • 29
    Apr 29th
    0 Files
  • 30
    Apr 30th
    0 Files

Top Authors In Last 30 Days

File Tags

Systems

packet storm

© 2022 Packet Storm. All rights reserved.

Services
Security Services
Hosting By
Rokasec
close