Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2018-8719 PoC — WordPress WP Security Audit Log插件安全漏洞

Source
Associated Vulnerability
Title:WordPress WP Security Audit Log插件安全漏洞 (CVE-2018-8719)
Description:WordPress是WordPress软件基金会的一套使用PHP语言开发的博客平台,该平台支持在PHP和MySQL的服务器上架设个人博客网站。WP Security Audit Log plugin是使用在其中的一个日志安全审计插件。 WordPress WP Security Audit Log插件3.1.1版本中存在安全漏洞,该漏洞源于程序没有限制wp-content/uploads/wp-security-audit-log/*文件的访问权限。攻击者可利用该漏洞获取敏感信息。
Description
WordPress WP Security Audit Log 3.1.1 plugin is susceptible to information disclosure. Access to wp-content/uploads/wp-security-audit-log/* files is not restricted. An attacker can obtain sensitive information, modify data, and/or execute unauthorized operations.
File Snapshot

id: CVE-2018-8719 info: name: WordPress WP Security Audit Log 3.1.1 - Information Disclosure au ...
Shenlong Bot has cached this for you
Remarks
    1. It is advised to access via the original source first.
    2. If the original source is unavailable, please email f.jinxu#gmail.com for a local snapshot (replace # with @).
    3. Shenlong has snapshotted the POC code for you. To support long-term maintenance, please consider donating. Thank you for your support.