header-logo
Suggest Exploit
vendor:
Counter
by:
wlhaan hacker
7,5
CVSS
HIGH
Remote File Upload
434
CWE
Product Name: Counter
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2020

MobPartner Counter Remote File Upload Vulnerability

A vulnerability exists in MobPartner Counter which allows an attacker to upload a malicious file to the server. The malicious file can be uploaded by editing the shell.php.pgif file and then accessing it via the upload.php page. This can allow an attacker to gain access to the server.

Mitigation:

Ensure that all file uploads are properly validated and sanitized before being accepted by the server.
Source

Exploit-DB raw data:

_____________________________________________________
MobPartner Counter) Remote File Upload Vulnerability )

#####################################################
# [+] Author : wlhaan hacker #
# [+] Email : iit@HoTMaiL.coM #
# [+] Site : www.sa-hacker.com/vb #
# [+] team wlhaan Hacker #
# [+] Dork : "MobPartner Counter" "upload files"
#####################################################

The exploit :

http://localhost/path/upload.php


edit shell

shell.php.pgif


Get now shell :

http://localhost/path/files/shell.php.pgif



and good luck :D

Thanks to : shooq hacker ..

#####################################################