99robots.comConfirmation
https://99robots.com/docs/wp-background-takeover-advertisements CVE-2018-9118
HIGHNuclei
99robots wp_background_takeover_advertisements Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
Record summary
CVE-2018-9118 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.
Description
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
Description source: CVE List
Exploitation context
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
wp_background_takeover_advertisementsBrowse 99robots / wp_background_takeover_advertisements | VulnCheck | Version data not supplied | |
Proofs of concept
1Catalogued exploits
ExploitDBWordPress Plugin Background Takeover < 4.1.4 - Directory TraversalExploitDB exploitby Colette ChamberlandNot analyzed1 file
Nuclei templates
1ProjectDiscoveryHIGHWordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File InclusionCVSS 7.5
WordPress 99 Robots WP Background Takeover Advertisements 4.1.4 is susceptible to local file inclusion via exports/download.php.
Impact
This vulnerability can lead to unauthorized access to sensitive files on the server, potentially exposing sensitive information or allowing for further exploitation.
Remediation
Upgrade to 4.1.15.
WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cveedbwordpresswp-pluginlfitraversalwp99robotsvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:99robots:wp_background_takeover_advertisements:*:*:*:*:*:wordpress:*:*
https://www.exploit-db.com/exploits/44417 https://wpvulndb.com/vulnerabilities/9056 https://99robots.com/docs/wp-background-takeover-advertisements/ https://nvd.nist.gov/vuln/detail/CVE-2018-9118 https://github.com/ARPSyndicate/cvemon
Source: ProjectDiscovery
References
4nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2018-9118 wpvulndb.com
https://wpvulndb.com/vulnerabilities/9056 44417exploit
https://www.exploit-db.com/exploits/44417