Skip to content

This allows attackers to to upload a PHP reverse shell on BoltWire 6.03 due to web misconfigurations.

Notifications You must be signed in to change notification settings

nesterXneo/BoltWire_6.03_File_Upload_Method

Folders and files

NameName
Last commit message
Last commit date

Latest commit

 

History

47 Commits
 
 
 
 

Repository files navigation

BoltWire_6.03_File_Upload_Method

FOR EDUCATIONAL PURPOSES ONLY

This allows attackers to manually upload a PHP reverse shell on BoltWire 6.03 within the admin panel. To do this, admin access is required and the "/dev/pages/" directory must be accessible through a web browser.

This was tested on Linux 4.19.0-16-amd64 #1 SMP Debian 4.19.181-1 x86_64 GNU/Linux.

Step 1: Login to admin page admin

Step 2: At the top, hit create to create page. Name it shell.php and copy/paste the reverse shell. Click Save. create

Step 3: Set up netcat listener. Go to the "/dev/pages" directory and click on your shell.php. pages

shell

About

This allows attackers to to upload a PHP reverse shell on BoltWire 6.03 due to web misconfigurations.

Resources

Stars

Watchers

Forks

Releases

No releases published

Packages

No packages published

Languages