Описание
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
Ссылки
- ProductRelease Notes
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
- ProductRelease Notes
- ExploitThird Party Advisory
- ExploitThird Party AdvisoryVDB Entry
Уязвимые конфигурации
Конфигурация 1Версия до 4.1.5 (исключая)
cpe:2.3:a:99robots:wp_background_takeover_advertisements:*:*:*:*:*:wordpress:*:*
EPSS
Процентиль: 99%
0.71307
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22
Связанные уязвимости
CVSS3: 7.5
github
больше 3 лет назад
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
EPSS
Процентиль: 99%
0.71307
Высокий
7.5 High
CVSS3
5 Medium
CVSS2
Дефекты
CWE-22