====================================================================================================================================
| # Title : MediaWiki 1.27.4 content sniffing Vulnerability |
| # Author : indoushka |
| # Tested on : windows 10 Français V.(Pro) / browser : Mozilla firefox 68.0.1(64-bit) |
| # Vendor : https://www.mediawiki.org/wiki/MediaWiki |
| # Dork : |
====================================================================================================================================
poc :
[+] The official website of paypal suffer from " content sniffing " .
[+] Use Payload : /w/api.php?action=Your New Link From Here=https://cxsecurity.com/
[+] https://www.mediawiki.org/w/api.php?action=Your%20New%20Link%20From%20Here=https://cxsecurity.com/ .
[+] https://www.mediawiki.org/w/api.php?action=Your%20New%20Link%20From%20Here=https://cxsecurity.com/&format=json
Greetings to :=========================================================================================================================
|
jericho * Larry W. Cashdollar * brutelogic* hyp3rlinx* 9aylas * shadow_00715 * LiquidWorm* |
|
=======================================================================================================================================