WordPress 插件“Post Export Import with Media”在所有 1.17.1 及更低版本中存在目录遍历漏洞,该漏洞由 参数引起。此漏洞允许具有管理员级别或以上权限的认证攻击者读取服务器上任意文件的内容,这些文件可能包含敏感信息。 攻击者需要上传一个精心构造的 ZIP 归档文件,其中包含一个 文件,并在该文件的 字段中嵌入目录遍历序列,同时为目标文件名指定一个允许的扩展名,以绕过版本 1.13.2 中引入的扩展名检查机制。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| wpazleen | Post Export Import with Media | ≤ 1.17.1 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| wpazleen | Post Export Import with Media | 0 ~ 1.17.1 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POCNo comments yet