KCFinder 2.2 - Arbitrary File Upload

EDB-ID:

15254

CVE:

N/A




Platform:

PHP

Date:

2010-10-15


: # Exploit Title: kcfinder 2.2 upload shell                                                 :
: # Date: 15/10/2010                                                                         :
: # Author: saudi0hacker                                                                     :  
: # Software Link:  http://kcfinder.sunhater.com/                                            :
: # Version: 2.x                                                                             :
: # Tested on: linux b0x                                                                     : 
: # Greetz to : All of my Friends                                                            :
----------------------------------------------------------------------------------------------

 [~] STEP 1 > Go to target link

     http://localhost/KCFinder/browse.php

 [~] STEP 2 > upload your shell as [shell.php.jpg]
  
 [~] Th3 End