Hack WordPress With Comment Upload Plugin

Google Dork
( use the following dork to find out vulnerable sites )

"inurl:/wp-content/plugins/easy-comment-uploads/upload-form.php"
/wp-content/plugins/easy-comment-uploads/upload-form.php 

Index of /wp-content/plugins/easy-comment-uploads

Select a site from the search result..
assume that,our selected url is


http://anysite.com/wp-content/plugins/easy-comment-uploads/upload-form.php 

now upload file as .txt or .asp.jpg

uploaded file will located here

/wp-content/uploads/2013/01/file_name

here 2013/01/ is uploading date of the file. If you upload the file on 01-06-2013 uploaded file link will be

/wp-content/uploads/2013/06/file_name

And You are Done :)
Previous
Next Post »
Thanks for your comment