Friday, March 20, 2015

Wordpress Plugins (error_log) Full Path Disclosure

###########################################
#-----------------------------------------
#[Copyright (c) 2015 | Dz Offenders Cr3w ]
#-----------------------------------------
###########################################
# >>    D_x . Made In Algeria . x_Z    << #
###########################################
#
# [>] Title : Wordpress Plugins (error_log) Full Path Disclosure
#
# [>] Author : KedAns-Dz
# [+] E-mail : ked-h (@hotmail.com)
# [+] FaCeb0ok : fb.me/K3d.Dz
# [+] TwiTter : @kedans
#
# [#] Platform : PHP / WebApp
# [+] Cat/Tag : Full Path Disclosure
#
# [<] <3 <3 Greetings t0 Palestine <3 <3
#
# [!] Vendor : wordpress.org
# [D] Download : ** Multiple Plugins **
# [V] Version : Wordpress x.ALL->latest (with vulnerable plugin installed)
#
#######################################################################
#
# [!] Description :
# -----------------
#
# - Wordpress Plugins (Multiple Plugins) is suffer from Full Path Disclosure
# allows remote attackers to disclosure the error_log revealing the full path script.

# > Moore Info see :
# [*] CWE-200
#
#####
#
# [!] Google Dork :
# -----------------
#
# - inurl:/wp-content/plugins/(*)/error_log
#
#####
#
# [>] Demos :
# -----------
#
# http://www.lifeintheoffice.com/wp-content/plugins/wordspew/error_log
# http://unitedfreeworld.com/wp-content/plugins/download-monitor/error_log
# http://threads13.com/wp-content/plugins/astickypostorderer/error_log
# http://www.ancira.us/jake/wp-content/plugins/astickypostorderer/error_log
# http://culturalcenter.gov.ph/wp-content/plugins/icg-ticketing-system/view/yespayments/error_log
# http://www.yootheniks.com/wp/wp-content/plugins/zingiri-tickets/extensions/error_log
# http://www.londonru.com/realestate/wp-content/plugins/firestorm-real-estate-plugin/error_log
# http://www.duomcgaw.com/lemonbarrettsreview/wp-content/plugins/re/error_log
# http://wazefte.com/portal/wp-content/plugins/fbc/inc/api/error_log
# http://www.vadimkolpakov.com/wp-content/plugins/limit-login-attempts/error_log
# http://bendsensigns.com/wp-content/plugins/peters-login-redirect/error_log
# http://www.rak-rijeka.org/wp-content/plugins/sidebar-login/error_log
# http://www.mercysong.com/wp-content/plugins/limit-login-attempts/error_log
# http://thebills.ca/wp-content/plugins/wp-mailinglist/views/email/error_log
# http://www.vadimkolpakov.com/wp-content/plugins/limit-login-attempts/error_log
#
# Mo in gooGlE *_^ ....
#
#####
#
# [F] Bug Fix :
# -------------
#
# - protect (error_log) with .htaccess and put it into the Plugin Path :D ;)
#   very easy : No ThanX by the way ^__^
#
####
#  <! THE END ^_* ! , Good Luck all <3 | 0-DAY Aint DIE ^_^ !>
#  Hassi Messaoud (30500) , 1850 city/hood si' elHaouass .<3
#---------------------------------------------------------------
# Greetings to my Homies : Meztol-Dz , Caddy-Dz , Kalashinkov3 ,
# Chevr0sky , Mennouchi.Islem , KinG Of PiraTeS , TrOoN , T0xic,
# & Jago-dz , Over-X , Kha&miX , Ev!LsCr!pT_Dz , Barbaros-DZ , &
# & KnocKout , Angel Injection , The Black Divels , kaMtiEz  , &
# & Evil-Dz , Elite_Trojan , MalikPc , Marvel-Dz , Shinobi-Dz, &
# & Keystr0ke , JF , r0073r , CroSs , Inj3ct0r/Milw0rm 1337day &
# =( packetstormsecurity.org * metasploit.com * OWASP & OSVDB )=
####

No comments:

Post a Comment

Note: Only a member of this blog may post a comment.