CVE-2015-5468
HIGH EXPLOITEDWP e-Commerce Shop Styling <2.6 - Path Traversal
Title source: llmExploitation Summary
CVE-2015-5468 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including Larry W. Cashdollar.
AI-analyzed exploit summary The exploit demonstrates a directory traversal vulnerability in the WordPress plugin wp-ecommerce-shop-styling v2.5, allowing unauthorized download of system files via unsanitized user input in the 'filename' parameter.
Description
Directory traversal vulnerability in the WP e-Commerce Shop Styling plugin before 2.6 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the filename parameter to includes/download.php.
Exploits (1)
The exploit demonstrates a directory traversal vulnerability in the WordPress plugin wp-ecommerce-shop-styling v2.5, allowing unauthorized download of system files via unsanitized user input in the 'filename' parameter.
References (4)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N