Is a request with wp-config.php in the query string ever legit ?
-
Is there any instance in which the config file is requested this way ?
GET /force-download.php?file=../wp-config.php
GET /wp-content/themes/epic/includes/download.php?file=wp-config.php
GET /wp-content/plugins/abtest/abtest_admin.php?action=../../../wp-config.phpThese specific examples I listed “here” are in fact some hacker looking for exploitable plugins. Does WP itself do this anywhere … or am I correct in surmising that neither WP nor any legit plugin would cuase requests like this..
or at least if they did, it would only be accessible under /wp-admin/GET /wp-admin/tools.php?page=backup_manager&download_backup_file=../wp-config.php
Viewing 4 replies - 1 through 4 (of 4 total)
Viewing 4 replies - 1 through 4 (of 4 total)
- The topic ‘Is a request with wp-config.php in the query string ever legit ?’ is closed to new replies.