CVE-2017-20248

HIGH

WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2017-20248. PoCs published by Ihsan Sencan.

AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Apptha Slider Gallery v1.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'imgname' parameter in the 'asgallDownload.php' script.

Description

Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests to asgallDownload.php with directory traversal sequences ../ to access sensitive files outside the intended directory.

Exploits (1)

exploitdb WORKING POC
by Ihsan Sencan · textwebappsphp
https://www.exploit-db.com/exploits/41568

This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Apptha Slider Gallery v1.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'imgname' parameter in the 'asgallDownload.php' script.

Classification
Working Poc 90%
Attack Type
Info Leak
Complexity
Trivial
Reliability
Reliable
Target: WordPress Plugin Apptha Slider Gallery v1.0
No auth needed
Prerequisites: Access to the vulnerable plugin path
devstral-2 · analyzed Jun 09, 2026 Full analysis →

References (3)

Core 3
Core References
Exploit exploit
ExploitDB-41568
https://www.exploit-db.com/exploits/41568
Product product
Official Product Homepage
https://www.apptha.com/
Third Party Advisory third-party-advisory
VulnCheck Advisory: WordPress Plugin Apptha Slider Gallery 1.0 Path Traversal File Download
https://www.vulncheck.com/advisories/wordpress-plugin-apptha-slider-gallery-path-traversal-file-download

Scores

CVSS v3 7.5
EPSS 0.0064
EPSS Percentile 45.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable yes
Technical Impact partial

Details

CWE
CWE-22
Status published
Products (1)
Apptha/Apptha Slider Gallery 1.0
Published Jun 09, 2026
Tracked Since Jun 09, 2026