Ueditor 1.2.2 - Unauthenticated File Upload
Posted on 30 November -0001
<HTML><HEAD><TITLE>ueditor 1.2.2 - Unauthenticated File Upload</TITLE><META http-equiv="Content-Type" content="text/html; charset=utf-8"></HEAD><BODY>###################### # Exploit Title : ueditor 1.2.2 - Unauthenticated File Upload # Exploit Author : Persian Hack Team # Vendor Homepage : https://www.nuget.org/packages/ueditor/ # Category: [ Webapps ] # Tested on: [ Win ] # Version: 1.2.2 # Date: 2016/08/28 ###################### # # PoC: # Find Vulnerable site And Select Image icon Then upload .jpg And .png File # File Path : www.site.com/ueditor/upload/image Best Way For Find Path on the video # Youtube Demo : https://www.youtube.com/watch?v=mX958GKk2b4 # ###################### # Discovered by : Mojtaba MobhaM Mail:kazemimojtaba@live.com # B3li3v3 M3 I will n3v3r St0p # Greetz : T3NZOG4N & FireKernel & Dr.Askarzade & Masood Ostad & Dr.Koorangi & Milad Hacking & JOK3R $ Mr_Mask_Black And All Persian Hack Team Members # Homepage : Persian-team.ir ###################### </BODY></HTML>