##################################################
# Exploit Title: [ [MOWPOP] Plugin WP-CONTENT In Wordpress Upload Exploitation]
# Date: [03-04-2012]
# Author: [ Hacker-Fire ]
# Category:: [ webapps]
# Google dork: [inurl:mowpop]
# Greetz Milw0rm : 1337day.com
# Demo site:
[1-http://www.updatedeinleben.com/wp-content/plu…wpop/submit.php]
[2-http://my-air-conditioner.com/wp-content/plu…wpop/submit.php]
[3-http://jennysweets.com/blog/wp-conten…wpop/submit.php]
# Tested on: [Windows & Linux ]
##################################################
1- Go to a website with the google dork and modify all url (without domain) with "/wp-content/plugins/mowpop/submit.php"
2- Take your Shell.php in text fields.
3- Open Tamper Data or HTTP Live Header.
4- Capture or Alter the upload.
5- Modify the content type with: "image/gif"
6- Drag'n'drop the borken picture obtained in the url bar.
7- Go to the url.
8- Ascend to the index.php with ".." url.
9- Upload your deface or other.
##########################################################
[»] Greetz to :
[ TrOon,Aghilas,r00t_dz,EliteTorjan,Vaga-hacker,xConsole,OverDz ]
[ & -> Th3 Viper,BriscO-Dz,LaMiN Dk, xV!rus , black hool ]
[ And all my Freinds + Algerian Hackers ]
##########################################################
# 1337day.com [2012-04-03]