CVE-2017-20248
HIGHWordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20248. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Apptha Slider Gallery v1.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'imgname' parameter in the 'asgallDownload.php' script.
Description
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory.
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Apptha Slider Gallery v1.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'imgname' parameter in the 'asgallDownload.php' script.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N