CVE-2015-9480
HIGH EXPLOITED NUCLEIRobotCPA 5 for WordPress - Path Traversal via f.php l Parameter
Title source: llmExploitation Summary
CVE-2015-9480 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including T3N38R15. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress plugin RobotCPA V5. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'l' parameter in the 'f.php' file with a base64-encoded path.
Description
The RobotCPA plugin 5 for WordPress has directory traversal via the f.php l parameter.
Exploits (1)
This exploit demonstrates a Local File Inclusion (LFI) vulnerability in the WordPress plugin RobotCPA V5. The vulnerability allows an attacker to read arbitrary files on the server by manipulating the 'l' parameter in the 'f.php' file with a base64-encoded path.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N