Record summary

CVE-2017-1000170 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.

Description

jqueryFileTree 2.1.5 and older Directory Traversal

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Jan 3, 2024 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Repository PoCs
1
Nuclei templates
1

Affected products and versions

2
ProductSourceVersion rangeStatus
VulnCheckVersion data not supplied
GitHub AdvisoryThrough 2.1.5affected

Proofs of concept

2

Catalogued exploits

ExploitDBWordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path TraversalExploitDB exploitby Nicholas FerreiraNot analyzed1 file
ExploitDB

PoC details

Repository PoCs

GitHubNickguitar/Jquery-File-Tree-1.6.6-Path-TraversalRepository PoCby NickguitarStars: 4Not analyzed2 files

16.5 KiB

GitHub

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File InclusionCVSS 7.5

WordPress Delightful Downloads Jquery File Tree versions 2.1.5 and older are susceptible to local file inclusion vulnerabilities via jqueryFileTree.

Impact

Allows an attacker to include arbitrary local files, potentially leading to unauthorized access or code execution.

Remediation

Update to the latest version of Delightful Downloads plugin or apply the patch provided by the vendor.

WeaknessesCWE-22
Authorsdwisiswant0
Template tagscve2017cvewordpresswp-pluginlfijqueryedbpacketstormjqueryfiletree_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:jqueryfiletree_project:jqueryfiletree:*:*:*:*:*:*:*:*

Source: ProjectDiscovery

References

3