CVE-2018-9118
HIGH EXPLOITED IN THE WILD NUCLEI99 Robots WP Background Takeover Advertisements < 4.1.5 - Path Traversal via Filename Parameter
Title source: llmExploitation Summary
CVE-2018-9118 has been observed exploited in the wild (reported by VulnCheck KEV, InTheWild.io). EIP tracks 1 public exploit from researchers including Colette Chamberland. A Nuclei detection template is also available.
AI-analyzed exploit summary This exploit demonstrates a directory traversal vulnerability in WP Background Takeover plugin versions <= 4.1.4. It allows an attacker to read arbitrary files on the server by manipulating the 'filename' parameter in the download.php script.
Description
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
Exploits (1)
This exploit demonstrates a directory traversal vulnerability in WP Background Takeover plugin versions <= 4.1.4. It allows an attacker to read arbitrary files on the server by manipulating the 'filename' parameter in the download.php script.
Nuclei Templates (1)
References (3)
Scores
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N