PT-2015-7577 · WordPress · Wordpress Font Plugin
Publicado
2015-10-16
·
Atualizado
2018-10-09
·
CVE-2015-7683
CVSS v2.0
4.0
Média
| Vetor | AV:N/AC:L/Au:S/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
WordPress Font plugin versions prior to 7.5.1
Description
The issue allows remote administrators to read arbitrary files due to an absolute path traversal vulnerability in the Font.php file of the Font plugin for WordPress. This can be achieved by providing a full pathname in the
url parameter to the "AjaxProxy.php" endpoint.Recommendations
For WordPress Font plugin versions prior to 7.5.1, update to version 7.5.1 or later to resolve the issue.
Exploit
Correção
Path traversal
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Wordpress Font Plugin