WordPress 插件 CodeArt Google MP3 Audio Player(google-mp3-audio-player)1.0.11 及之前版本存在未经身份验证的任意文件读取漏洞。攻击者通过在 direct_download.php 的 file 参数中提供路径穿越载荷,即可读取敏感文件。攻击者无需身份验证即可请求 ../../wp-config.php 等路径,下载包含数据库凭证和密钥的配置信息,从而导致网站完全被攻破。该漏洞的利用证据最早于 2023 年 10 月 19 日被 Shadowse
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Damjan | CodeArt Google MP3 Audio Player | ≤ 1.0.11 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Damjan | CodeArt Google MP3 Audio Player | 0 ~ 1.0.11 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet