header-logo
Suggest Exploit
vendor:
Flex File Manager
by:
Mr.MLL
7,5
CVSS
HIGH
Shell Upload Vulnerability
434
CWE
Product Name: Flex File Manager
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: N/A
Related CWE: N/A
CPE: N/A
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2010

( Flex File Manager ) Shell Upload Vulnerability

A vulnerability exists in Flex File Manager which allows an attacker to upload a malicious shell to the server. The attacker can then access the shell by navigating to the data directory of the application.

Mitigation:

Ensure that the application is configured to only allow the upload of files with the appropriate file extensions.
Source

Exploit-DB raw data:

====================================================
 ( Flex File Manager ) Shell Upload Vulnerability
====================================================

#  ( Flex File Manager ) Shell Upload Vulnerability
 
 
# Author: Mr.MLL
# Published: 2010-04-19
# Verified: yes
# Download Exploit Code
# Download N/A
 
=========
 
 
 
# Software :  http://www.castlesblog.com/public/flexfm.zip
# Vendor   :  http://www.castlesblog.com/
# Contact  :  Y-3@hotmail.com
# Home     :  http://sec-r1z.com/
 
 
=========
 
[~] Exploit
 
    http://localhost/flexfm/


[~] expl0it: Your Shell shell.php.jpg or shell.php  And Upload Site.  And  go to


     
[~] http://localhost/flexfm/data/  shell name


=========
 
# Greetz
 
 
all Muslims hacker & Q!sR QaTaR & Big Hacker & h311 c0d3   & All My Friends
 
=========

# Thanks : milw0rm.com & inj3ct0r.com & exploit-db.com  & offsec.com  

exit ,, / Praise be to God for the blessing of Islam