############################################################################################# # # # Exploit Title : Wordpress Easy Comment Uploads Shell Upload Vulnerability # # # # Author : Nafsh # # # # Discovered By : Tapco Security & Research Lab # # # # Home : sec-lab.ir # # # # Contact : research [at] sec-lab [dot] ir # # # # Date : 4/8/2012 - 13:33 # # # # Source : plugins.svn.wordpress.org/easy-comment-uploads/tags/0.60/upload.php # # # # DorK : intext:"Invalid referer" inurl:"upload.php" # # # ############################################################################################# # POC: In Previous Version You Can Upload Your Shell With Image MimeType But In New Version You Should Bypass Uploader With Http Refrer Phishing And Change Refrer To /wp-admin # Source :