Senin, 08 Agustus 2011

TinyFileBrowser ~ Remote file Upload Vulnerability

Title : TinyFileBrowser  ~ Remote file Upload Vulnerability
Google Dork : "inurl:tinybrowser/upload.php" 


Lets Start : Open google.com/ncr or you country dOmain like Google.co.in and enter This dork
"inurl:tinybrowser/upload.php" 


 Vulnerable website's title will TinyBrowser :: Upload in search results 
and in sOme sites it will show you website directory in title :) 
click on Vulnerable website only ... igNore sOme extra results 


Now You'll Got a page Like this image 




For uploading Your files click on upload ... and click on browse to view Your Uploaded File :)
you can upload [.html],[.txt],[.jpg],[.gif],[.bmp] [.php not allowed] but atleast you can try as 
php.jpg :P ... but in sOme websites you can upload images and txt file Only .. but 
dont worry ... u can notify your deface as image or text file :D

Must levae a comment if you like this Post :) 


"Nothing is impossible in this world even Nobody is Perfect "

Tidak ada komentar:

Posting Komentar

"Custom Upload" Sql injection remote php shell upload vulnreblity

Google Dork : inurl:customupload.html Poc : fileupload.html Author : NoEntryPhc SQL injection vulnreblity :  Goto Google.com and ...