WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Snap Creek Duplicator是使用在其中的一个WordPress网站迁移插件。 WordPress Snap Creek Duplicator 1.3.28之前版本和Duplicator Pro 3.8.7.1之前版本中存在路径遍历漏洞。攻击者可通过向duplicator_download或duplicator_init发送带有‘../’序列的‘file’
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
10-question deep dive: root cause, exploitation, mitigation, urgency. Read summary free, full version requires login.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| - | n/a | n/a | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | snapcreek_duplicator file read vulnerability https://www.cvedetails.com/cve/CVE-2020-11738/ | https://github.com/raghu66669999/wordpress-snapcreek | POC Details |
| 2 | WordPress Duplicator 1.3.24 & 1.3.26 are vulnerable to local file inclusion vulnerabilities that could allow attackers to download arbitrary files, such as the wp-config.php file. According to the vendor, the vulnerability was only in two versions v1.3.24 and v1.3.26, the vulnerability wasn't present in versions 1.3.22 and before. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2020/CVE-2020-11738.yaml | POC Details |
| 3 | None | https://github.com/Threekiii/Awesome-POC/blob/master/CMS%E6%BC%8F%E6%B4%9E/WordPress%20Duplicator%20duplicator.php%20%E4%BB%BB%E6%84%8F%E6%96%87%E4%BB%B6%E8%AF%BB%E5%8F%96%E6%BC%8F%E6%B4%9E%20CVE-2020-11738.md | POC Details |
No public POC found.
Login to generate AI POC| CVE-2020-10642 | Rockwell Automation RSLinx Classic 安全漏洞 | |
| CVE-2020-10646 | Fuji Electric V-Server Lite 缓冲区错误漏洞 | |
| CVE-2020-11736 | GNOME file-roller 后置链接漏洞 | |
| CVE-2019-13916 | Cypress Semiconductor WICED Studio 缓冲区错误漏洞 | |
| CVE-2020-11734 | CyberSolutions CyberMail 跨站脚本漏洞 | |
| CVE-2020-8430 | Stormshield Network Security 输入验证错误漏洞 | |
| CVE-2020-11673 | WordPress Responsive Poll 授权问题漏洞 | |
| CVE-2020-9478 | Rubrik 操作系统命令注入漏洞 | |
| CVE-2020-8148 | Ubiquiti Networks UniFi Cloud Key 授权问题漏洞 | |
| CVE-2020-11731 | WordPress Media Library Assistant 跨站脚本漏洞 | |
| CVE-2020-11732 | WordPress Media Library Assistant 信息泄露漏洞 |
No comments yet