Record summary

CVE-2013-7240 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory TraversalExploitDB exploitby Henri SaloNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress Plugin Advanced Dewplayer 1.2 - Directory TraversalCVSS 5

A directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

Impact

An attacker can exploit this vulnerability to access sensitive files, potentially leading to unauthorized disclosure of sensitive information.

Remediation

Update to the latest version of the Advanced Dewplayer plugin or remove it if it is not actively used.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscvecve2013wp-pluginlfiedbseclistswordpresswesterndealvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:westerndeal:advanced_dewplayer:1.2:*:*:*:*:*:*:*
Google: inurl:"/wp-content/plugins/advanced-dewplayer/"

Source: ProjectDiscovery

References

5