Record summary

CVE-2018-9118 has a selected CVSS score of 7.5 (high); EIP currently links 1 catalogued exploit and 1 Nuclei template.

Description

exports/download.php in the 99 Robots WP Background Takeover Advertisements plugin before 4.1.5 for WordPress has Directory Traversal via a .. in the filename parameter.

Description source: CVE List

Exploitation context

Known exploitation

VulnCheck KEV
Listed · Apr 12, 2021 · VulnCheck
Reported exploitation
Observed · VulnCheck

Available material

Catalogued exploits
1
Nuclei templates
1

Affected products and versions

1
ProductSourceVersion rangeStatus

wp_background_takeover_advertisements

Browse 99robots / wp_background_takeover_advertisements
VulnCheckVersion data not supplied

Proofs of concept

1

Catalogued exploits

ExploitDBWordPress Plugin Background Takeover < 4.1.4 - Directory TraversalExploitDB exploitby Colette ChamberlandNot analyzed1 file
ExploitDB

PoC details

Nuclei templates

1
ProjectDiscoveryHIGHWordPress 99 Robots WP Background Takeover Advertisements <=4.1.4 - Local File InclusionCVSS 7.5

WordPress 99 Robots WP Background Takeover Advertisements 4.1.4 is susceptible to local file inclusion via exports/download.php.

Impact

This vulnerability can lead to unauthorized access to sensitive files on the server, potentially exposing sensitive information or allowing for further exploitation.

Remediation

Upgrade to 4.1.15.

WeaknessesCWE-22
Authors0x_Akoko
Template tagscve2018cveedbwordpresswp-pluginlfitraversalwp99robotsvkevvuln
CVSS vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CPE: cpe:2.3:a:99robots:wp_background_takeover_advertisements:*:*:*:*:*:wordpress:*:*

Source: ProjectDiscovery

References

4