angel shell bypass shell Shell download Litespeed Bypass Shell C99 shell r57 shell wso shell Bypass shell Symlink shell cgi telnet 404 shell forbidden shell anon shell privshells private shell privateshell
12:19
# Exploit Title: Live Chat Unlimited v2.8.3 Stored XSS Injection
# Google Dork: inurl:"wp-content/plugins/screets-lcx"
# Date: 2019/06/25
# Exploit Author: m0ze
# Vendor Homepage: https://screets.com/
# Software Link: https://codecanyon.net/item/wordpress-live-chat-plugin/3952877
# Version: 2.8.3
# Tested on: Windows 10 / Parrot OS
# CVE : -
Info:
Weak security measures like bad input field data filtering has been
discovered in the «Live Chat Unlimited». Current version of this
premium WordPress plugin is 2.8.3.
PoC:
Go to the demo website https://site.com/try/lcx/night-bird/ and open chat window by clicking on «Open/close» link, then click on «Online mode» to go online. Use your payload inside input field and press [Enter].
Provided exaple payloads working on the admin area, so it's possible to steal admin cookies or force a redirect to any other
website.
Example #1: <!--<img src="--><img src=x onerror=(alert)(`m0ze`)//">m0ze
Example #2: <!--<img src="--><img src=x onerror=(alert)(document.cookie)//">m0ze
bypass shell Stupidc0de php shell download Litespeed Bypass Shell
bypass shell Stupidc0de php shell ,jumping shell, config shell
Command, Config Grabber, Domain Viewer , Mass Tool , Cpanel Tool,
Bypass Tools , File Creator, Create RDP, Jumping, Dumper tool
dhanush shell bypass shell -litespeed bypass shell
shell helix bypass shell Piyasada çok kişi tarafından kullanılan shell'in editlenmiş versiyonu.
İçerisine jumping,passwd,c1ve Cgi telnet eklenmiş olan shell ile daha hızlı ve kolay çalışabilirsiniz.
0 yorum:
Yorum Gönderme