Sunday, July 31, 2016

CuteNews 2.0.3 Remote File Upload Vulnerability

Hello fans, Now I will share this simple tutorial called" CuteNews Remote File Upload Vulnerable exploit"this exploit is very very easy to understand
Now here we go
Dork: intext:powered by cute news "
and start cheking for vul webs, if web vuln you'll get something like this image
Click register and fill in all the columns correctly
After registration, Log In and Go to Personal options, Select Upload Avatar Example: shell.jpg use tamper data & Rename File shell.jpg to shell.php
Afta that check your uploaded file here www.site.com/cutenews/uploads/avatar_Username_FileName.php
your shell will open for you happy defacing :D ..
use this web as example www.ambvetamatoviolini.it/CuteNews/?register
Thanks To : Mr . 3RR0R |PhantomGhost Team | ITSulawesi Sec

No comments:

Post a Comment