CVE-2013-7240
WordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory Traversal
Record summary
CVE-2013-7240 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
Directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.
Exploitation context
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Advanced Dewplayer - 'download-file.php' Script Directory TraversalExploitDB exploitby Henri SaloNot analyzed1 file
Nuclei templates
1ProjectDiscoveryMEDIUMWordPress Plugin Advanced Dewplayer 1.2 - Directory TraversalCVSS 5
A directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.
Impact
An attacker can exploit this vulnerability to access sensitive files, potentially leading to unauthorized disclosure of sensitive information.
Remediation
Update to the latest version of the Advanced Dewplayer plugin or remove it if it is not actively used.
Source: ProjectDiscovery