405 B
405 B
So far we know that adding ?static=1
to a wordpress URL should leak its secret content
Here are a few ways to manipulate the returned entries:
order
withasc
ordesc
orderby
m
withm=YYYY
,m=YYYYMM
orm=YYYYMMDD
date format
In this case, simply reversing the order of the returned elements suffices and http://wordpress.local/?static=1&order=asc
will show the secret content: