CVE-2016-10924
HIGH EXPLOITED NUCLEIzedna_ebook_download < 1.2 - Path Traversal
Title source: llmExploitation Summary
CVE-2016-10924 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 6 public exploits from researchers including alealeluyah, alebrestado, 808ale. A Nuclei detection template is also available.
AI-analyzed exploit summary This repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress plugin 'ebook-download' (versions < 1.2). The exploit allows unauthorized file reads by manipulating the 'ebookdownloadurl' parameter in a crafted GET request.
Description
The ebook-download plugin before 1.2 for WordPress has directory traversal.
Exploits (6)
This repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress plugin 'ebook-download' (versions < 1.2). The exploit allows unauthorized file reads by manipulating the 'ebookdownloadurl' parameter in a crafted GET request.
This repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress plugin 'ebook-download' (versions < 1.2). The exploit allows unauthorized file reads by manipulating the 'ebookdownloadurl' parameter in a GET request.
This repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress plugin 'ebook-download' (versions < 1.2). The exploit allows unauthorized file reads by manipulating the 'ebookdownloadurl' parameter in a GET request.
The repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress ebook-download plugin (<1.2). The script bruteforces process IDs to leak sensitive files via path traversal.
The repository contains a functional Python script that exploits a directory traversal vulnerability (CVE-2016-10924) in the WordPress ebook-download plugin (<1.2). The script brute-forces process IDs to read sensitive files like /proc/sched_debug and /proc/[pid]/cmdline.
The repository contains a functional Python script that exploits CVE-2016-10924, a file disclosure vulnerability in the WordPress eBook Download plugin (version 1.1). The script brute-forces process IDs via the vulnerable `filedownload.php` endpoint to leak `/proc/<PID>/cmdline` contents.
Nuclei Templates (1)
References (1)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N