Wednesday, August 3, 2016

HOW TO DEFACE WORDPRESS THEMES QUALIFIRE..

Hi All
, now i will post Wp Qualfire Themes hacking tutorial..


-Dork: inurl:"wp-content/themes/
qualifire


-Exploit : /wp-content/themes/qualifire/
scripts/admin/uploadify/uploadify.php



If it shows blank page that means it Vuln

CSRF





if shell succesful upload it will display "1" in a blank page


how to Access your shell: target.com/shellname.php


NOTE: not all webz accept .php file,so if php fails during uploading try jpg,phtml,txt or html


Good_Bye :D

2 comments: