CVE-2018-9118
HIGH EXPLOITED IN THE WILD NUCLEI99robots WP Background Takeover Advertisements - Path Traversal
Title source: ruleDescription
exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.
Exploits (1)
exploitdb
WORKING POC
by Colette Chamberland · textwebappsphp
https://www.exploit-db.com/exploits/44417
Nuclei Templates (1)
WordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File Inclusion
HIGHby 0x_Akoko
Scores
CVSS v3
7.5
EPSS
0.7131
EPSS Percentile
98.7%
Attack Vector
NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Details
VulnCheck KEV
2021-04-12
InTheWild.io
2021-04-12
CWE
CWE-22
Status
published
Products (1)
99robots/wp_background_takeover_advertisements
< 4.1.5
Published
Apr 12, 2018
Tracked Since
Feb 18, 2026