CVE-2014-5465
Download Shortcode < 0.2.3 - Path Traversal via File Parameter
Title source: llmExploitation Summary
EIP tracks 1 public exploit for CVE-2014-5465. PoCs published by Mehdi Karout & Christian Galeone.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress Download ShortCode plugin (version 0.2.3). The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'file' parameter in the 'force-download.php' script.
Description
Directory traversal vulnerability in force-download.php in the Download Shortcode plugin 0.2.3 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress Download ShortCode plugin (version 0.2.3). The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'file' parameter in the 'force-download.php' script.