CVE-2014-5181
Last.fm Rotation 1.0 - Path Traversal
Record summary
CVE-2014-5181 has a selected CVSS score of 5.0; EIP currently links 1 Nuclei template.
Description
Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryMEDIUMLast.fm Rotation 1.0 - Path TraversalCVSS 5
Directory traversal vulnerability in lastfm-proxy.php in the Last.fm Rotation (lastfm-rotation) plugin 1.0 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the snode parameter.
Impact
Remote attackers can read arbitrary files on the server, potentially leading to information disclosure or further exploitation.
Remediation
Update to the latest version of the plugin or apply security patches to fix the vulnerability.
Source: ProjectDiscovery