################################################################################################## #Exploit Title : Ukora CMS Shell Upload vulnerability #Author : Jagriti Sahu AKA incredible #Vendor : http://ukora.com #Download Link : https://github.com/baskuis/ukoracms #version affected : all #Date : 23/07/2014 #Discovered at : IndiShell Lab #Love to : Surbhi, Mradula and Harry ################################################################################################## //////////////////////// /// Overview: //////////////////////// Ukora CMS is affected from remote file upload vulnerability and attacker can upload php shell to website easily /////////////////////////////// // Vulnerability Description: /////////////////////////////// vulnerability is due to assets/upl/uploadFile.php file in which there is no check during file upload attacker need to forward file upload request to this file with PHP shell and file Extension /////////////////////// /// exploit code //// ///////////////////////