IMCE Remote File Upload Vulnerability 06-14-2013, 06:54 AM
#1
Hello Hack Community.
Through this tutorial, I'm going to teach you how to upload your deface page or maybe even shells on remote servers of websites.
The dork for finding vulnerable websites is : inurl:"/imce?dir=" intitle:"File Browser"
The vulnerable url will be something like this : http://site.com/imce?dir=
Once you open up the URL, it should look like this :
![[Image: iberp17dDCHp7w.png]](http://i1.minus.com/iberp17dDCHp7w.png)
Now, on the left panel, click on the blue folder.
The blue folder is the root and clicking on it, takes you to the root directory. If it says Access Denied, go to another site.
Now, click on the upload button as shown in the screenshot.
Select your deface page in HTML format or shell in PHP format and click on Upload.
After your file is uploaded, it should look like this :
![[Image: ibbPaPmM0QT0lY.png]](http://i1.minus.com/ibbPaPmM0QT0lY.png)
The file you've uploaded will be selected automatically.
To view your deface page, double click on the selected file.
Here's mine :
![[Image: ivicu8rLfGTG3.png]](http://i7.minus.com/ivicu8rLfGTG3.png)
And you're done!!! Your deface page or shell got uploaded and executed.
:whistle:
Remember, our forum is an ethical hacking forum. Do not abuse, threaten or blackmail the owner of the website through your deface page or shell.
Try as far as possible to keep it ethical.
This tutorial is for educational purposes only. Please do not harm anybody and avoid getting into trouble.
Please do not forget to give feedback.
Through this tutorial, I'm going to teach you how to upload your deface page or maybe even shells on remote servers of websites.
The dork for finding vulnerable websites is : inurl:"/imce?dir=" intitle:"File Browser"
The vulnerable url will be something like this : http://site.com/imce?dir=
Once you open up the URL, it should look like this :
![[Image: iberp17dDCHp7w.png]](http://i1.minus.com/iberp17dDCHp7w.png)
Now, on the left panel, click on the blue folder.
The blue folder is the root and clicking on it, takes you to the root directory. If it says Access Denied, go to another site.
Now, click on the upload button as shown in the screenshot.
Select your deface page in HTML format or shell in PHP format and click on Upload.
After your file is uploaded, it should look like this :
![[Image: ibbPaPmM0QT0lY.png]](http://i1.minus.com/ibbPaPmM0QT0lY.png)
The file you've uploaded will be selected automatically.
To view your deface page, double click on the selected file.
Here's mine :
Spoiler:
![[Image: ivicu8rLfGTG3.png]](http://i7.minus.com/ivicu8rLfGTG3.png)
And you're done!!! Your deface page or shell got uploaded and executed.
:whistle:Remember, our forum is an ethical hacking forum. Do not abuse, threaten or blackmail the owner of the website through your deface page or shell.
Try as far as possible to keep it ethical.
This tutorial is for educational purposes only. Please do not harm anybody and avoid getting into trouble.
Please do not forget to give feedback.




![[Image: 2YpkRjy.png]](http://i.imgur.com/2YpkRjy.png)
![[+]](https://sinister.li/images/modern/collapse_collapsed.png)
Was just saying this might be exploitable, but it's not so vulnerable (I couldn't exploit it).