PT-2010-1482 · WordPress · Wp-Lytebox

Published

2010-03-05

·

Updated

2017-09-19

·

CVE-2009-4672

CVSS v2.0

7.5

High

VectorAV:N/AC:L/Au:N/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions WP-Lytebox plugin version 1.3
Description A directory traversal issue in the main.php file of the WP-Lytebox plugin allows remote attackers to include and execute arbitrary local files. This is achieved by using a .. (dot dot) in the pg parameter of a vulnerable API endpoint.
Recommendations For WP-Lytebox plugin version 1.3, consider disabling the main.php file or restricting access to it until a patch is available. Avoid using the pg parameter in the affected endpoint until the issue is resolved.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2009-4672

Affected Products

Wp-Lytebox