CVE-2012-0896

NUCLEI

count_per_day < 3.1.1 - Unauthenticated Path Traversal via Download Parameter

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2012-0896. PoCs published by 6Scan. A Nuclei detection template is also available.

AI-analyzed exploit summary This exploit demonstrates arbitrary file download and reflected XSS vulnerabilities in the Count-per-day WordPress plugin. The file download PoC leverages a direct path traversal to retrieve sensitive files, while the XSS PoC injects malicious script tags via user-controlled input.

Description

Absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

Exploits (1)

exploitdb WORKING POC VERIFIED
by 6Scan · textwebappsphp
https://www.exploit-db.com/exploits/18355

This exploit demonstrates arbitrary file download and reflected XSS vulnerabilities in the Count-per-day WordPress plugin. The file download PoC leverages a direct path traversal to retrieve sensitive files, while the XSS PoC injects malicious script tags via user-controlled input.

Classification
Working Poc 100%
Attack Type
Info Leak | Xss
Complexity
Trivial
Reliability
Reliable
Target: Count-per-day WordPress plugin < 3.1.1
No auth needed
Prerequisites: WordPress installation with vulnerable Count-per-day plugin · Network access to the target
devstral-2 · analyzed Feb 16, 2026 Full analysis →

Nuclei Templates (1)

Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access
MEDIUMby daffainfo

References (8)

Core 8
Core References
Exploit exploit x_refsource_exploit-db
http://www.exploit-db.com/exploits/18355
Exploit vdb-entry x_refsource_osvdb
http://osvdb.org/78270
Vendor Advisory third-party-advisory x_refsource_secunia
http://secunia.com/advisories/47529
Third Party Advisory, VDB Entry vdb-entry x_refsource_xf
https://exchange.xforce.ibmcloud.com/vulnerabilities/72385
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/51402

Scores

EPSS 0.0083
EPSS Percentile 75.0%

Details

CWE
CWE-22
Status published
Products (6)
count_per_day_project/count_per_day 2.2
count_per_day_project/count_per_day 2.15
count_per_day_project/count_per_day 2.15.1
count_per_day_project/count_per_day 2.16
tom_braider/count_per_day 1.0
tom_braider/count_per_day < 3.1
Published Jan 20, 2012
Tracked Since Feb 18, 2026