----------------------------------------------------------------------------------------- Author : Ahmad Pay Date : March, 25 2009 Location : Bojonegoro, Indonesia Critical : High Impact : System Access Where : From Remote --------------------------------------------------------------------------- Application : WeBid version : <= 0.7.3 RC9 Vendor : http://sourceforge.net/projects/simpleauction -------------------------------------------------------------------------- Vulnerability: ~~~~~~~~~~ Anyone can upload shell php with extension eg: shell.php.jpg. Poc/Exploit: ~~~~~ http://www.example.com/[path]/upldgallery.php Then after upload shell right click to the pages to find your shell path ####################################### eg: