Showing Up Source Code

Disclosed: 2017-05-04 13:31:51 By kashif To udemy
Unknown
Vulnerability Details
Hello Sir! I have just seen vulnerability in your website: https://blog.udemy.com in this website your website is showing the PHP code of a file named [wordpress-importer.php] link of this file is listed below: https://blog.udemy.com/wp-content/uploads/2010/09/wordpress-importer.php_.txt I have also attached the proof of concept you can see. Solve Your Issue as soon as possible because a hacker can attack your website by knowing that this is WordPress website and he may find vulnerability in the WordPress he can exploit that vulnerability in your website also Waiting For Your Reply.
Actions
View on HackerOne
Report Stats
  • Report ID: 135620
  • State: Closed
  • Substate: informative
  • Upvotes: 3
Share this report