Описание
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.
Ссылки
- Exploit
- Patch
- Exploit
- Exploit
- Exploit
- Patch
- Exploit
- Exploit
Уязвимые конфигурации
Конфигурация 1Версия до 1.3.9 (включая)
cpe:2.3:a:thecartpress:thecartpress_ecommerce_shopping_cart:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 94%
0.144
Средний
4 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
github
больше 3 лет назад
Directory traversal vulnerability in the TheCartPress eCommerce Shopping Cart (aka The Professional WordPress eCommerce Plugin) plugin for WordPress before 1.3.9.3 allows remote administrators to read arbitrary files via a .. (dot dot) in the tcp_box_path parameter in the checkout_editor_settings page to wp-admin/admin.php.
EPSS
Процентиль: 94%
0.144
Средний
4 Medium
CVSS2
Дефекты
CWE-22