############################################################### # Exploit Title: Wordpress Husker-Portfolio plugins CSRF File Upload Vulnerability # Author: Ashiyane Digital Security Team # Date: 12/09/2013 # Vendor : http://www.huskerinfotech.com/ # Software Link : http://downloads.wordpress.org/plugin/huskerportfolio.0.3.zip # Google dork: inurl:/wp-content/plugins/huskerPortfolio/ # Tested on: Windows/Linux ############################################################### 1)Exploit : = = = = = =
choose a file:

2)Exploit Demo : = = = = = = = http://secondbaptistoxford.org/wp-content/plugins/huskerPortfolio/huskerPortfolio.php http://floralicious.ie/wp-content/plugins/huskerPortfolio/huskerPortfolio.php http://oakforestinteriors.co.uk/wp-content/plugins/huskerportfolio/huskerPortfolio.php http://oakforestinteriors.co.uk/wp-content/plugins/huskerportfolio/huskerPortfolio.php # #### #### #### #### #### #### #### #### # # http://[Target]/wp-content/plugins/huskerPortfolio/upload/[file] # #### #### #### #### #### #### #### #### # # BY T3rm!nat0r5 # E-mail : poya.terminator@gmail.com # #### #### #### #### #### #### #### #### #