RE: IMCE Remote File Upload Vulnerability 06-21-2013, 10:55 PM
#6
I've just had a look yesterday and there are actually not. I spent pretty much time trying to edit the POST data with Tamper and no way to either get access to the root directory (not the one in the upload manager, 'cause files are actually saved in a subdirectory) or to upload shells or whatever. If you upload a PHP, ASP or whatever file it gets renamed to *.txt.
My Bitcoin address: 1AtxVsSSG2Z8JfjNy9KNFDUN6haeKr7LiP
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U
If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize
Give me money by visiting www.google.com here: http://coin-ads.com/6Ol83U
If you want a Bitcoin URL shortener/advertiser, please, use this referral: http://coin-ads.com/register.php?refid=noize

![[+]](https://sinister.li/images/modern/collapse_collapsed.png)