CVE-2015-9406
HIGH EXPLOITED NUCLEImTheme-Unus < 2.3 - Path Traversal via CSS File Parameter
Title source: llmExploitation Summary
CVE-2015-9406 has been observed exploited in the wild (reported by VulnCheck KEV).
EIP tracks 1 public exploit from researchers including Khwanchai Kaewyos, including a Metasploit module auxiliary/scanner/http/wp_mobileedition_file_read.
A Nuclei detection template is also available.
AI-analyzed exploit summary This Metasploit module exploits a directory traversal vulnerability in the WordPress Mobile Edition plugin (version 2.2.7) to read arbitrary files with web server privileges. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.
Description
Directory traversal vulnerability in the mTheme-Unus theme before 2.3 for WordPress allows an attacker to read arbitrary files via a .. (dot dot) in the files parameter to css/css.php.
Exploits (1)
This Metasploit module exploits a directory traversal vulnerability in the WordPress Mobile Edition plugin (version 2.2.7) to read arbitrary files with web server privileges. It sends a crafted HTTP GET request with traversal sequences to access files outside the intended directory.
Nuclei Templates (1)
body="wp-content/themes/mTheme-Unus/"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N