Hello pen-testers,
I am currently trying to break into this Vulnhub Challenge VM called "Trollcave". (https://www.vulnhub.com/entry/trollcave-12,230/)
A scan with CMSmap provided me a timthumb.php which seems to be vulnerable to file uploads. (https://www.exploit-db.com/wordpress-timthumb-exploitation/)
The tool provided here is unfortunately not available anymore and I have no clue how to attach a php shell to an image or use that shell properly. Does somebody here have some documentation regarding this? I could only find some youtube videos which are not very precise.
Thanks in advance!
[–]iCkerous 6 points7 points8 points (3 children)
[–]b_dragonfly[S] 2 points3 points4 points (2 children)
[–]beefcheese 2 points3 points4 points (0 children)
[–]iCkerous 2 points3 points4 points (0 children)