Title:WordPress Localize My Post 路径遍历漏洞 (CVE-2018-16299) Description:WordPress是WordPress基金会的一套使用PHP语言开发的博客平台。该平台支持在PHP和MySQL的服务器上架设个人博客网站。Localize My Post是使用在其中的一个帖子本地化插件。 WordPress Localize My Post 1.0版本中的ajax/include.php文件存在路径遍历漏洞,该漏洞源于程序未过滤‘file’参数。攻击者可利用该漏洞包含任意文件。
Description
WordPress Localize My Post 1.0 is susceptible to local file inclusion via the ajax/include.php file parameter.
File Snapshot
id: CVE-2018-16299
info:
name: WordPress Localize My Post 1.0 - Local File Inclusion
author: 0x
...
Shenlong Bot has cached this for you
Remarks
1. It is advised to access via the original source first.2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.