ProfileCMS version 1.0 suffers from a remote shell upload vulnerability.
cc9a0d86156cc39fe512179d41031b7cProfileCMS v1.0 Shell Upload Exploit
Demo : http://slrate.com/
You can direct upload PHP shell instead of image while creating profile at this script, For example http://slrate.com/profiles here you can direct upload shell instead of images.
Dorks :
"Total Generators & Widgets"
"Powered By ProfileCMS v1.0"
Comments
No comments yet, be the first!