Wordpress directories/files visible to internet

Disclosed: 2017-03-08 14:13:46 By tk0 To ui
Medium
Vulnerability Details
#Issue During my testing I noticed that ubnt website `https://directory.corp.ubnt.com` seems to leak some data into internet. Wordpress directory `https://directory.corp.ubnt.com/wp-content/uploads/` is showing files which I suppose shouldn't be visible to internet. I noticed that these files include UBNT-employee email addresses (including personal?), pictures etc. #Reproduction Just open URL https://directory.corp.ubnt.com/wp-content/uploads/ and start browsing folders/files. Most "juicy" stuff can be seen in these folders: ██████████ BR, -Tomi
Actions
View on HackerOne
Report Stats
  • Report ID: 201984
  • State: Closed
  • Substate: resolved
  • Upvotes: 18
Share this report