Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2020-11732 PoC — WordPress Media Library Assistant 信息泄露漏洞

Source
Associated Vulnerability
Title:WordPress Media Library Assistant 信息泄露漏洞 (CVE-2020-11732)
Description:WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Media Library Assistant是使用在其中的一个媒体库助手插件。 Wordpress Media Library Assistant 2.82之前版本中的mla_gallery link = download存在信息泄露漏洞。远程攻击者可借助特制URL利用该漏洞获取敏感信息或在服务器上执行任意代码。
Description
Media Library Assistant plugin for WordPress before 2.82 contains a local file inclusion caused by unsanitized mla_gallery link parameter, letting attackers include arbitrary local files, exploit requires access to the vulnerable link.
File Snapshot

id: CVE-2020-11732 info: name: Media Library Assistant < 2.82 - Unauthenticated Limited Local Fil ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.