==================================================================================================================================== | # Title : Advanced Form builder v 2.0 File Upload Image Cropper Take Photo System unrestricted file upload Vulnerability | | # Author : indoushka | | # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 66.0(64-bit) | | # Vendor : https://codecanyon.net/item/advanced-form-builder-file-upload-image-cropper-take-photo-system/23594027?s_rank=1 | | # Dork : | ==================================================================================================================================== poc : [+] Dorking İn Google Or Other Search Enggine [+] unauthenticated arbitrary file upload vulnerability. [+] Go to : https://127.0.0.1/fucw.glossytruthcom/file_upload.php [+] Select your ev!l & upload it [+] https://127.0.0.1/fucw.glossytruthcom/server/php/files/info.txt ==Greetings to :========================================================================================================================= | jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* thelastvvv *Zigoo.eg * moncet | =========================================================================================================================================