Joomla shell upload

To understand where a shell is uploaded in the previously mentioned exploit, we will upload a basic command execution shell manually from the administrator panel.

After exploitation, once we have logged in successfully as an admin, we can upload a shell from the templates menu. The following screenshot shows the administration panel of Joomla:

From the panel's menu, we click on Extensions | Templates | Templates, as shown:

We are redirected to the Templates page, where all the templates currently uploaded are listed, including ...

Get Hands-On Web Penetration Testing with Metasploit now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.