Advertisement






Simple File Uploader Explorer and Manager v1 unrestricted file upload Vulnerability

CVE Category Price Severity
N/A CWE-434 Not specified High
Author Risk Exploitation Type Date
Unknown High Remote 2018-01-01
CPE
cpe:Not available
CVSS EPSS EPSSP
CVSS:4.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018010003

Below is a copy:

Simple File Uploader Explorer and Manager v1 unrestricted file upload Vulnerability
====================================================================================================================================
| # Title     : Simple File Uploader Explorer and Manager v1 unrestricted file upload Vulnerability                                |
| # Author    : indoushka                                                                                                          |
| # email     : [email protected]                                                                                           |
| # Tested on : windows 10 Franais V.(Pro)                                                                                        |
| # Version   : v1                                                                                                                 |
| # Vendor    : https://codecanyon.net/item/simple-file-uploader-explorer-and-manager-php-based-secured-file-manager/18393053      |  
| # Dork      : http://nelliwinne.net/                                                                                             |
====================================================================================================================================


poc :

Simple File Uploader and Explorer is a simple PHP Script to upload files and manage them. 
The drag and drop file uploader is the main feature of this script. 
It allows you to upload multiple files very fast and easy way. 
All files are stored in a writable folder (fileFolder). 
Once the files are uploaded they can be viewed in Download Files section. 
Also you can search files, view thumbnails and Download Files


[+] Dorking n Google Or Other Search Enggine .

[+] go to upload section : /uploader_page.php

[+] choose your file : Ev!l.php & click start upload .

[+] go to file manager . filemanager_page.php

so you found your evil.php but when you click to view they give you link to download

http://demos.nelliwinne.net/SimpleFileUploaderExplorer/download.php?id=ZmlsZUZvbGRlci94LnBocA==

like we see the end of link coded by base64 ( ZmlsZUZvbGRlci94LnBocA== )

when we decrypt they give as the real place of file : fileFolder/x.php

http://demos.nelliwinne.net/SimpleFileUploaderExplorer/fileFolder/x.php

Greetz :----------------------------------------------------------------------------------------
                                                                                               |
jericho * Larry W. Cashdollar * shadow0075 * djroot.dz *Gjoko 'LiquidWorm' Krstic              |
                                                                                               |
================================================================================================

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum