####################################################### # # [+] Exploit Title: FileChucker v4.56t-e07 File Upload Vulnerability # [+] Google Dork: inurl:/cgi-bin/filechucker.cgi OR "intext:File Upload by Encodable" OR inurl:/cgi-bin/filechucker.pl # [+] Date: 24-07-2013 # [+] Exploit Author: Iranian_Dark_Coders_Team # [+] Home : www.idc-team.net # [+] Discovered By : Black.Hack3r # [+] Category: webapps # [+] Software Link: http://encodable.com/filechucker/trial/filechucker.zip # [+] Vendor Homepage: http://encodable.com/filechucker/ # [+] Version: 4.56t-e07 # [+] Tested on: Windows 7 # ####################################################### # # [+] Exploit: # # [+] http://localhost/[path]/cgi-bin/filechucker.cgi # [+] http://localhost/[path]/cgi-bin/filechucker.pl # # ####################################################### # # [+] Proof: # # [+] http://localhost/[path]/cgi-bin/filechucker.cgi # [1] You must enter the requested information first. # [2] Please Click on the Browse and Select a file ( .htm , .html , .gif , .jpg , .png , .txt ) # [3] http://localhost/[path]/upload/files/Black.Hack3r.htm OR Black.Hack3r.html # ####################################################### # # [+] Demo site: # # [+] http://encodable.com/filechucker/#demo # [+] http://encodable.com/uploaddemo/ # [+] http://www.middadmit.org/cgi-bin/filechucker.cgi # [+] http://www.proprintidaho.com/cgi-bin/filechucker.cgi # [+] http://www.golfillustrated.com/upload/ # ####################################################### # # [+] Discovered By : Black.Hack3r # [+] We Are : M.R.S.CO,Black.Hack3r,N3O,UB313 # [+] SpTnx : Mr.Cicili,Sec4ever,shahram black hat,C@M!S3Я_H3X,3is@,HOt0N,All Members In www.idc-team.net/cc # [+] Home : http://www.idc-team.net # #######################################################