Saturday, January 28, 2017

KindEdior Remote File Upload exploit

KindEdior Remote File Upload exploit


 KindEdior Remote File Upload exploit 

 
 
Google Dork :
 intitle:index of? inurl:kindeditor
inurl:examples/uploadbutton.html

 exploit:http://www.vulnrabewebsite.com/path/kindeditor/examples/uploadbutton.html

Choose any website from google search results and goto vulnrabel url
like http://www.vulnrabewebsite.com/kindeditor/examples/uploadbutton.html
now click on upload n select your file, it will be automaticly uploaded,
 and youll got your uploaded file Link/URL there, and if you cant get your uploaded file link then goto http:// www.vulnrabewebsite.com/path/kindeditor/attached/file/
and youll se lot of folders here, click on last folder and in the folder click on last file, its your uploaded file ..Enjoy & Must leave a Comment if you want more exploit like that, because 
new articles posting depends on old articles popularity

Live Demo : 
http://www.arimlab.com/themes/default/js/kindeditor/examples/uploadbutton.html
http://www.arimlab.com/themes/default/js/kindeditor/attached/file/20120115/20120115142540_32112.html

Available link for download