Thanks : KHC,PH,ColdHackers and all Kurdish script
kiddies/hax0rs/lame/l33t/
d0rk : "neuron blog powered"
------------------------------------------------------------------------
Vulnerability details:
This blog the prepare persons to in "/admin" page to the entrance of far
away did't hinder. To reach of far away to be done is necessary just a
"click" :) www.site.com/admin
<input type="submit" name="submit" value="add blog item!" />
</form>
Note : If you join the admin modules add blog will get out. You can throw
the file to website :) you can find your file in the link is
/example/uploads or anyway can you see the homapage :)
Now relative the PoC
http://www.site.com/admin/blog-add.php
http://www.site.com/uploads/phpshell.php :]
and upload your files :) there is two is choose 1) photo 2) documents
Feedback :
If you have additional information or notice any errors regarding this security advisory, please use contact form or email us at info()securityreason()com.