Friday, March 20, 2015

Wordpress Plugin (wp-super-cache) Absolute Path Traversal

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
 -----------------------------------------
 [Copyright (c) 2015 | Dz Offenders Cr3w ]
 -----------------------------------------

###########################################
# >>    D_x . Made In Algeria . x_Z    << #
###########################################
#
# [>] Title : Wordpress Plugin (wp-super-cache) Absolute Path Traversal
#
# [>] Author : KedAns-Dz
# [+] E-mail : ked-h (@hotmail.com)
# [+] FaCeb0ok : fb.me/K3d.Dz
# [+] TwiTter : @kedans
#
# [#] Platform : PHP / WebApp
# [+] Cat/Tag : Directury & Path Traversal
#
# [<] <3 <3 Greetings t0 Palestine <3 <3
#
# [!] Vendor : wordpress.org
# [D] Download : https://wordpress.org/plugins/wp-super-cache/
# [V] Version : x.ALL -> latest 1.4.2
#
#######################################################################
#
# [!] Description :
# -----------------
#
# - Wordpress Plugin (wp-super-cache) is suffer from Absolute Path Traversal
# his allows attackers to traverse the file system to access files or directories
# that are outside of the restricted directory.
#
# [*] CWE-36
#
#####
#
# [!] Google Dork :
# -----------------
#
# - inurl:/wp-content/plugins/wp-super-cache/
#
#####
#
# [>] Demos :
# -----------
#
# http://gossipextra.com/wp-content/cache/supercache/
# http://popathon.org/learningtocount/wp-content/cache/supercache/
# http://college-deparcieux.fr/radio/wp-content/cache/supercache/
# http://nutritionwonderland.com/wp-content/plugins/wp-super-cache/
# http://www.houstonkraft.com/wp-content/plugins/wp-super-cache/
# Mo in gooGlE *_^ ....
#
#####
#
# [F] Bug Fix :
# -------------
#
# - Just put index.html & .htaccess into the Plugin Path :D ;)
#   very easy : No ThanX by the way ^__^
#
####
#  <! THE END ^_* ! , Good Luck all <3 | 0-DAY Aint DIE ^_^ !>
#  Hassi Messaoud (30500) , 1850 city/hood si' elHaouass .<3
#---------------------------------------------------------------
# Greetings to my Homies : Meztol-Dz , Caddy-Dz , Kalashinkov3 ,
# Chevr0sky , Mennouchi.Islem , KinG Of PiraTeS , TrOoN , T0xic,
# & Jago-dz , Over-X , Kha&miX , Ev!LsCr!pT_Dz , Barbaros-DZ , &
# & KnocKout , Angel Injection , The Black Divels , kaMtiEz  , &
# & Evil-Dz , Elite_Trojan , MalikPc , Marvel-Dz , Shinobi-Dz, &
# & Keystr0ke , JF , r0073r , CroSs , Inj3ct0r/Milw0rm 1337day &
# =( packetstormsecurity.org * metasploit.com * OWASP & OSVDB )=
####

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.