PGR-Filemanager | Arbitrary File Upload

CVE-2019-6690 CWE-434 $500 High
Unknown High Remote 2021-08-06
CVSS:4.0/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H 0.02192 0.50148

PGR-Filemanager | Arbitrary File Upload
Exploit Title : PGR-Filemanager | Arbitrary File Upload
# Vendor Homepage : N/A
# Discovered By : KimiHmei7
# Author Homepage : HTTPS://TEGALSEC.ORG

# Google Dork : inurl:/plugins/pgrfilemanager/

# Step by Step
1. Dorking on google for find site
2. Add this exploit /PGRFileManager.php . 
example: ~
If you see File Uploader mean that site is vulnerable. 
3. Upload shell with extension .txt
example : ~ shell.txt
4. Then rename into php extension.
5. You can find your shell in directory /public/upload/[folder]/shell.php
example :[folder]/shell.php

# Demo?
No demo. Find vulnerable sites with your brain! 
Greetz :  Family Attack Cyber - Tegal1337

