nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2015-9480 CVE-2015-9480
HIGHNuclei
robot-cpa robotcpa Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2015-9480 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
robotcpaBrowse robot-cpa / robotcpa | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin RobotCPA V5 - Local File InclusionExploitDB exploitby T3N38R15Not analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHWordPress RobotCPA 5 - Directory TraversalCVSS 7.5
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
Impact
An attacker can access sensitive files on the server, potentially leading to unauthorized access, data leakage, or further exploitation.
Remediation
Update to the latest version of the WordPress RobotCPA 5 plugin to fix the directory traversal vulnerability.
WeaknessesCWE-22
Authorsdaffainfo
Template tagscve2015cvewp-pluginlfiedbwordpressrobot-cpavulnvkev
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:robot-cpa:robotcpa:5:*:*:*:*:wordpress:*:*
Google: inurl:"/wp-content/plugins/robotcpa"
https://www.exploit-db.com/exploits/37252 https://nvd.nist.gov/vuln/detail/CVE-2015-9480 https://github.com/ARPSyndicate/kenzer-templates
Source: ProjectDiscovery
References
2Exploit Databaseexploit
https://www.exploit-db.com/exploits/37252