Skip to content

Latest commit

 

History

History
11 lines (11 loc) · 665 Bytes

Catch Themes Demo Import.md

File metadata and controls

11 lines (11 loc) · 665 Bytes

Exploit Title: WrodPress Plugin Catch Themes Demo Import —— Arbitrary File Upload

Exploit Author: Thinkland Security Team

Version : V 1.6.1

Vulnerability Type: Arbitrary File Upload

Tested on Windows 10 、XAMPP

Vulnerability proof:

1.Appearance》Catch Themes Demo Import》Manual demo files upload》Upload Trojan file:2.php image
image
image