WordPress Drag And Drop Multi File Uploader Remote Code Execution

Discussion in 'News Aggregator' started by Packet Storm, 5 Jun 2020.

  1. Packet Storm

    Packet Storm Guest

    This Metasploit module exploits a file upload feature of Drag and Drop Multi File Upload - Contact Form 7 for versions prior to 1.3.4. The allowed file extension list can be bypassed by appending a %, allowing for php shells to be uploaded. No authentication is required for exploitation.

    Continue reading...
     

Share This Page

Loading...