CVE-2012-0896
NUCLEIcount_per_day < 3.1.1 - Unauthenticated Path Traversal via Download Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2012-0896. PoCs published by 6Scan. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates arbitrary file download and reflected XSS vulnerabilities in the Count-per-day WordPress plugin. The file download PoC leverages a direct path traversal to retrieve sensitive files, while the XSS PoC injects malicious script tags via user-controlled input.
Description
Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.
Exploits (1)
This exploit demonstrates arbitrary file download and reflected XSS vulnerabilities in the Count-per-day WordPress plugin. The file download PoC leverages a direct path traversal to retrieve sensitive files, while the XSS PoC injects malicious script tags via user-controlled input.