Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2014-5368 PoC — WordPress WP Content Source Control插件‘download.php’目录遍历漏洞

Source
Associated Vulnerability
Title:WordPress WP Content Source Control插件‘download.php’目录遍历漏洞 (CVE-2014-5368)
Description:WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。WP Content Source Control(wp-source-control)是其中的一个主题目录及帖子/网页的源代码管理插件。 WordPress WP Content Source Control (wp-source-control)插件3.0.0及之前版本的downloadfiles/download.php脚本中‘file_get_content
Description
A directory traversal vulnerability in the file_get_contents function in downloadfiles/download.php in the WP Content Source Control (wp-source-control) plugin 3.0.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the path parameter.
File Snapshot

id: CVE-2014-5368 info: name: WordPress Plugin WP Content Source Control - Directory Traversal ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.