Voodoo CMS Aribitarty File Upload


Dork   ;   /contactos-6-m/contacto.htm

Exploit   ;   localhost/path   /voodoo-admin/uploader.php                    Type CSRF : qqfile
                   localhost/path   /voodoo-admin/upload.php                      Type CSRF : Filedata
                   localhost/path   /uploader.php                                           Type CSRF : qqfile

Vuln  ;   {"error":"No files were uploaded.","IdGeneral":"","NameGeneral":""}

CSRF   ;   www.pastebin.com/FawrTz41



Support File Upload   ;   jpeg, jpg, png, bmp, zip, xls, xlsx, doc, docx, csv, tiff, tif

Result   ;   https://localhost/path   /voodoo-admin/files_tmp/RANDOM-CODE.ext

Random-Code.ext   ;


Thanks!