Arbitrary File Upload


The target Textpattern CMS instance on the 192.168.207.219 host supports file upload.

Payload successfully uploaded.

┌──(kali㉿kali)-[~/PEN-200/PG_PLAY/driftingblues6]
└─$ curl -s http://$IP/textpattern/files/shell.php

Invoking the RevShells

Initial Foothold established to the driftingblues(192.168.207.219) host as the www-data account via arbitrary file upload.