packetstormsecurity.com
http://packetstormsecurity.com/files/161900/WordPress-Delightful-Downloads-Jquery-File-Tree-1.6.6-Path-Traversal.html CVE-2017-1000170
HIGHNuclei
jqueryFileTree vulnerable to Directory Traversal
Record summary
CVE-2017-1000170 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit, 1 repository PoC, and 1 Nuclei template.
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
jqueryfiletreeBrowse jqueryfiletree_project / jqueryfiletree | VulnCheck | Version data not supplied | |
jqueryfiletreeBrowse npm / jqueryfiletree | GitHub Advisory | Through 2.1.5 | affected |
Proofs of concept
2Catalogued exploits
ExploitDBWordPress Plugin Delightful Downloads Jquery File Tree 1.6.6 - Path TraversalExploitDB exploitby Nicholas FerreiraNot analyzed1 file
Repository PoCs
GitHubNickguitar/Jquery-File-Tree-1.6.6-Path-TraversalRepository PoCby NickguitarStars: 4Not analyzed2 files
Nuclei templates
1ProjectDiscoveryHIGHWordPress Delightful Downloads Jquery File Tree 2.1.5 - Local File InclusionCVSS 7.5
WordPress Delightful Downloads Jquery File Tree versions 2.1.5 and older are susceptible to local file inclusion vulnerabilities via jqueryFileTree.
Impact
Allows an attacker to include arbitrary local files, potentially leading to unauthorized access or code execution.
Remediation
Update to the latest version of Delightful Downloads plugin or apply the patch provided by the vendor.
WeaknessesCWE-22
Authorsdwisiswant0
Template tagscve2017cvewordpresswp-pluginlfijqueryedbpacketstormjqueryfiletree_projectvkevvuln
CVSS vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:jqueryfiletree_project:jqueryfiletree:*:*:*:*:*:*:*:*
https://www.exploit-db.com/exploits/49693 https://github.com/jqueryfiletree/jqueryfiletree/issues/66 http://packetstormsecurity.com/files/161900/WordPress-Delightful-Downloads-Jquery-File-Tree-1.6.6-Path-Traversal.html https://nvd.nist.gov/vuln/detail/CVE-2017-1000170 https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
3github.com
https://github.com/jqueryfiletree/jqueryfiletree/issues/66 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2017-1000170