97108vdb entry
http://www.securityfocus.com/bid/97108 CVE-2015-1000005
HIGHNuclei
WordPress Candidate Application Form <= 1.3 - Local File Inclusion
Record summary
CVE-2015-1000005 has a selected CVSS score of 7.5 (high); EIP currently links 1 Nuclei template.
Description
Remote file download vulnerability in candidate-application-form v1.0 wordpress plugin
Description source: CVE List
Exploitation context
Available material
- Nuclei templates
- 1
Nuclei templates
1ProjectDiscoveryHIGHWordPress Candidate Application Form <= 1.3 - Local File InclusionCVSS 7.5
WordPress Candidate Application Form <= 1.3 is susceptible to arbitrary file downloads because the code in downloadpdffile.php does not do any sanity checks.
Impact
An attacker can exploit this vulnerability to read sensitive files on the server.
Remediation
Update to the latest version of the plugin.
WeaknessesCWE-22
AuthorsdhiyaneshDK
Template tagscve2015cvewpscanwordpresswp-pluginlfiwpcandidate-application-form_projectvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:candidate-application-form_project:candidate-application-form:1.0:*:*:*:*:wordpress:*:*
https://wpscan.com/vulnerability/446233e9-33b3-4024-9b7d-63f9bb1dafe0 https://nvd.nist.gov/vuln/detail/CVE-2015-1000005 http://www.vapidlabs.com/advisory.php?v=142 https://github.com/ARPSyndicate/cvemon https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
3vapidlabs.com
http://www.vapidlabs.com/advisory.php?v=142 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-1000005