CVE-2017-20250
HIGHWordPress Plugin Mac Photo Gallery 3.0 Arbitrary File Download
Title source: cnaExploitation Summary
EIP tracks 1 public exploit for CVE-2017-20250. PoCs published by Ihsan Sencan.
AI-analyzed exploit summary This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Mac Photo Gallery v3.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'albid' parameter in the 'macdownload.php' script.
Description
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to macdownload.php with directory traversal sequences to access sensitive files like wp-load.php outside the intended plugin directory.
Exploits (1)
This exploit demonstrates an arbitrary file download vulnerability in WordPress Plugin Mac Photo Gallery v3.0. The vulnerability allows an attacker to download sensitive files by manipulating the 'albid' parameter in the 'macdownload.php' script.
References (3)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N