ProfileCMS 1.0 - Arbitrary File Upload
Author: r00t@zapak.com
type: webapps
platform: php
port:
date_added: 2007-10-28
date_updated:
verified: 1
codes: OSVDB-45297;CVE-2007-5720
tags:
aliases:
screenshot_url:
application_url:
ProfileCMS v1.0 Shell Upload Exploit
Demo : http://slrate.com/
You can direct upload PHP shell instead of image while creating profile at this script, For example http://slrate.com/profiles here you can direct upload shell instead of images.
Dorks :
"Total Generators & Widgets"
"Powered By ProfileCMS v1.0"
# milw0rm.com [2007-10-29]