Spaw is a Vunerablity, you Can Upload your deface & Shell Easily in Vunerable websites
Lets Start
open www.google.com
enter The Dork inurl:"spaw2/dialogs/"
or
inurl:"spaw2/uploads/files/"
You will Got results Like this "Index of/ spaw2/dialogs/"
or : site.com/abc/spaw2/uploads/files/abc/abc.pdf
Now replace The Spaw2/Uploads/abc/abc ur with this url
Lets Start
open www.google.com
enter The Dork inurl:"spaw2/dialogs/"
or
inurl:"spaw2/uploads/files/"
You will Got results Like this "Index of/ spaw2/dialogs/"
or : site.com/abc/spaw2/uploads/files/abc/abc.pdf
Now replace The Spaw2/Uploads/abc/abc ur with this url
for example i got this website
so Now i will replcae
with
Now the URL is
Now you will Got a window like this (click to see)
if you want to Upload deface page then Select files option ... and i f you want to upload shell then select image option and upload your shell as shell.php;,jpg
see You uploaded deface here
www.site.com/profile/spaw2/uploads/
comment here if any prOblem