Vulnerability CVE-2015-5482


Published: 2015-08-18

Description:
Directory traversal vulnerability in the GD bbPress Attachments plugin before 2.3 for WordPress allows remote administrators to include and execute arbitrary local files via a .. (dot dot) in the tab parameter in the gdbbpress_attachments page to wp-admin/edit.php.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
WordPress GD bbPress Attachments 2.1 Local File Inclusion
Tom Adams
13.07.2015

Type:

CWE-98

(Improper Control of Filename for Include/Require Statement in PHP Program ('PHP File Inclusion'))

CVSS2 => (AV:N/AC:L/Au:S/C:N/I:N/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
4/10
2.9/10
8/10
Exploit range
Attack complexity
Authentication
Remote
Low
Single time
Confidentiality impact
Integrity impact
Availability impact
None
None
Partial
Affected software
Dev4press -> Gd bbpress attachments 

 References:
https://packetstormsecurity.com/files/132656/wpgdbbpress-lfi.txt
https://security.dxw.com/advisories/local-file-include-vulnerability-in-gd-bbpress-attachments-allows-attackers-to-include-arbitrary-php-files/
https://wordpress.org/plugins/gd-bbpress-attachments/changelog/
https://wpvulndb.com/vulnerabilities/8087

Copyright 2024, cxsecurity.com

 

Back to Top