We read every piece of feedback, and take your input very seriously.
To see all available qualifiers, see our documentation.
There was an error while loading. Please reload this page.
1 parent 55b8d67 commit 5ea062bCopy full SHA for 5ea062b
modules/exploits/unix/webapp/wp_downloadmanager_upload.rb
@@ -59,7 +59,7 @@ def exploit
59
'vars_get' => { 'task' => 'wpdm_upload_files' }
60
)
61
62
- if res && res.code == 200 && res.body && res.body.length > 0 && res.body !~ /filename.+\.php$/
+ if res && res.code == 200 && res.body && res.body.length > 0 && res.body =~ /#{Regexp.escape(filename)}$/
63
uploaded_filename = res.body
64
register_files_for_cleanup(uploaded_filename)
65
print_status("#{peer} - File #{uploaded_filename} successfully uploaded")
0 commit comments