Advertisement






Simogeo Filemanager - Arbitrary File Upload

CVE Category Price Severity
CVE-2018-20742 CWE-434 $700 High
Author Risk Exploitation Type Date
Stark High Remote 2017-12-10
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2017120062

Below is a copy:

Simogeo Filemanager - Arbitrary File Upload
##########################################
# Exploit Title : Simogeo Filemanager - Arbitrary File Upload
# vendor home : https://github.com/simogeo/Filemanager
# Contact : https://www.facebook.com/izzadiine/
# Date : 11:41 PM 12/9/2017
# Exploit Author: Misterklio
# Category: Webapps 
# Language: PHP 
# Tested on: windows 7 / FireFox
##########################################
#################   Dorks  ##################
# Search target with Google Dorking 
# Dork : inurl:/js/filemanager/index.html
################ Poc ######################
Poc : /filemanager/index.html
#################  Vuln Upload  #############
# Exemple : 
https://ayalonmotors.co.il/js/filemanager/index.html #CO.IL
http://www.durhamcityssp.org.uk/js/filemanager/index.html
https://provincia.fermo.it/js/fileManager/index.html


##########################################
# Enjoy Discovered by Mister klio 
##########################################

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum