Record summary

CVE-2015-4414 has a selected CVSS score of 5.0; EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

Directory traversal vulnerability in download_audio.php in the SE HTML5 Album Audio Player (se-html5-album-audio-player) plugin 1.1.0 and earlier for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Description source: CVE List

Exploitation context

Available material

Catalogued exploits
1
Nuclei templates
1

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin SE HTML5 Album Audio Player 1.1.0 - Directory TraversalExploitDB exploitby Larry W. CashdollarNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryMEDIUMWordPress SE HTML5 Album Audio Player 1.1.0 - Directory TraversalCVSS 5

WordPress SE HTML5 Album Audio Player 1.1.0 contains a directory traversal vulnerability in download_audio.php that allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter.

Impact

An attacker can exploit this vulnerability to access sensitive files on the server, potentially leading to unauthorized disclosure of sensitive information.

Remediation

Update to the latest version of WordPress SE HTML5 Album Audio Player or apply the vendor-supplied patch to fix the directory traversal vulnerability.

WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2015cvewordpresswp-pluginlfiedbpacketstormse_html5_album_audio_player_projectvuln
CVSS vector: CVSS:2.0/AV:N/AC:L/Au:N/C:P/I:N/A:N
CPE: cpe:2.3:a:se_html5_album_audio_player_project:se_html5_album_audio_player:*:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/se-html5-album-audio-player"

Source: ProjectDiscovery

References

6